UBUNTU-CVE-2020-8244
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-8244
UBUNTU-CVE-2020-8244
Summary:
Details: A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.
References: https://ubuntu.com/security/CVE-2020-8244, https://hackerone.com/reports/966347, https://github.com/rvagg/bl/commit/d3e240e3b8ba4048d3c76ef5fb9dd1f8872d3190, https://ubuntu.com/security/notices/USN-5098-1, https://ubuntu.com/security/notices/USN-5159-1, https://www.cve.org/CVERecord?id=CVE-2020-8244
Affected packages
Package
Name: node-bl
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
