7.7

CVE-2021-23386

Remote Memory Exposure

This affects the package dns-packet before 5.2.2. It creates buffers with allocUnsafe and does not always fill them before forming network packets. This can expose internal application memory over unencrypted network when querying crafted invalid domain names.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dns-packet ProjectDns-packet SwPlatformnode.js Version < 1.3.4
Dns-packet ProjectDns-packet SwPlatformnode.js Version >= 2.0.0 < 5.2.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.43% 0.695
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
report@snyk.io 7.7 1.8 5.3
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L
CWE-909 Missing Initialization of Resource

The product does not initialize a critical resource.

https://github.com/mafintosh/dns-packet/commit/25f15dd0fedc53688b25fd053ebbdffe3d5c1c56
Patch
Third Party Advisory
https://hackerone.com/bugs?subject=user&amp%3Breport_id=968858
Third Party Advisory
Permissions Required
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1295719
Patch
Third Party Advisory
https://snyk.io/vuln/SNYK-JS-DNSPACKET-1293563
Patch
Third Party Advisory