Out-of-bounds read In nodejs
Description
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 10.21.0~dfsg-1 | ||
alpine v3.14 | 12.18.0-r0 | ||
alpine v3.20 | 12.18.0-r0 | ||
debian 12 | 10.21.0~dfsg-1 | ||
alpine v3.22 | 12.18.0-r0 | ||
alpine v3.11 | 12.20.1-r0 | ||
alpine v3.12 | 12.18.3-r0 | ||
alpine v3.13 | 12.18.0-r0 | ||
alpine v3.15 | 12.18.0-r0 | ||
alpine v3.16 | 12.18.0-r0 |
1-10 of 21
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.
References
1. 2. 3. 4.