8.8

CVE-2020-36406

Exploit
uWebSockets 18.11.0 and 18.12.0 has a stack-based buffer overflow in uWS::TopicTree::trimTree (called from uWS::TopicTree::unsubscribeAll). NOTE: the vendor's position is that this is "a minor issue or not even an issue at all" because the developer of an application (that uses uWebSockets) should not be allowing the large number of triggered topics to accumulate
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Uwebsockets ProjectUwebsockets Version18.11.0 SwPlatformnode.js
   LinuxLinux Kernel Version-
Uwebsockets ProjectUwebsockets Version18.12.0 SwPlatformnode.js
   LinuxLinux Kernel Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.52% 0.713
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=25381
Patch
Third Party Advisory
Exploit
Issue Tracking
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/uwebsockets/OSV-2020-1695.yaml
Third Party Advisory
https://github.com/uNetworking/uWebSockets/commit/03fca626a95130ab80f86adada54b29d27242759
Patch
Third Party Advisory