CVE-2014-5256
Node.js 0.8 before 0.8.28 and 0.10 before 0.10.30 does not consider the possibility of recursive processing that triggers V8 garbage coll… (CVE-2014-5256)
noneEPSS 3.3%
Description
Node.js 0.8 before 0.8.28 and 0.10 before 0.10.30 does not consider the possibility of recursive processing that triggers V8 garbage collection in conjunction with a V8 interrupt, which allows remote attackers to cause a denial of service (memory corruption and application crash) via deep JSON objects whose parsing lets this interrupt mask an overflow of the program stack.
Metrics
Severity
none
52.55
no public PoC known
87.6 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Published
2014-09-05 17:00 UTC
—
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
nodejs
nodejs
References & sources
- http://www-01.ibm.com/support/docview.wss?uid=swg21684769x_refsource_CONFIRM
- http://secunia.com/advisories/61260third-party-advisoryx_refsource_SECUNIA
- http://advisories.mageia.org/MGASA-2014-0516.htmlx_refsource_CONFIRM
- https://github.com/joyent/node/commit/530af9cb8e700e7596b3ec812bad123c9fa06356x_refsource_CONFIRM
- http://blog.nodejs.org/2014/07/31/v8-memory-corruption-stack-overflow/x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:142vendor-advisoryx_refsource_MANDRIVA
IDCVE-2014-5256