Skip to content
This repository has been archived by the owner on Feb 18, 2022. It is now read-only.

Security Alert - Package: dns-packet; Severity: HIGH #796

Open
phenggeler opened this issue Jan 25, 2022 · 1 comment
Open

Security Alert - Package: dns-packet; Severity: HIGH #796

phenggeler opened this issue Jan 25, 2022 · 1 comment

Comments

@phenggeler
Copy link

phenggeler commented Jan 25, 2022

    Affected package: dns-packet
    Ecosystem: NPM
    Affected version range: < 1.3.2

    Summary: Potential memory exposure in dns-packet
    Description: This affects the package dns-packet before versions 1.3.2 and 5.2.2. It creates buffers with allocUnsafe and does not always fill them before forming network packets. This can expose internal application memory over unencrypted network when querying crafted invalid domain names.
    identifiers: [{'type': 'GHSA', 'value': 'GHSA-3wcq-x3mq-6r9p'}, {'type': 'CVE', 'value': 'CVE-2021-23386'}]

    Fixed Version: 1.3.2
    Created Date = January 25, 2022

    

    ---
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants