Buffer Overflow in node-weakauras-parser
Moderate severity
GitHub Reviewed
Published
Sep 3, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Package
Affected versions
>= 1.0.4, < 1.0.5
>= 2.0.0, < 2.0.2
>= 3.0.0, < 3.0.1
Patched versions
1.0.5
2.0.2
3.0.1
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 3, 2020
Last updated
Jan 9, 2023
Affected versions of
node-weakauras-parser
are vulnerable to a Buffer Overflow. Theencode_weakaura
function fails to properly validate the input size. A buffer of 13835058055282163711 bytes causes an overflow on 64-bit systems.Recommendation
Upgrade to versions 1.0.5, 2.0.2, 3.0.1 or later.
References