Back

MEDIUM

nodejs-stringstream: out-of-bounds read leading to uninitialized memory exposure

Published Dec 3, 2020

Description

Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).

Affected products

Remediation

Red Hat statement

Red Hat Quay include stringstream as a dependency of Karma. Karma is only used at build time, and not at runtime reducing the impact of this vulnerability to low.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 3, 2020
Updated Aug 5, 2024
Reserved Dec 3, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 16, 2020
GHSA-MF6X-7MM4-X2G7