CVE-2021-23386 – dns-packet
Package
Manager: npm
Name: dns-packet
Vulnerable Version: >=2.0.0 <5.2.2 || >=0 <1.3.2
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS: 0.01115 pctl0.7736
Details
Potential memory exposure in dns-packet This affects the package dns-packet before versions 1.3.2 and 5.2.2. It creates buffers with allocUnsafe and does not always fill them before forming network packets. This can expose internal application memory over unencrypted network when querying crafted invalid domain names.
Metadata
Created: 2021-05-24T19:51:04Z
Modified: 2021-05-26T20:11:00Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-3wcq-x3mq-6r9p/GHSA-3wcq-x3mq-6r9p.json
CWE IDs: ["CWE-200", "CWE-908"]
Alternative ID: GHSA-3wcq-x3mq-6r9p
Finding: F017
Auto approve: 1