Asymmetric denial of service - ReDoS In pbkdf2
Description
pbkdf2 rehashes long passwords on every iteration, enabling denial of service
Summary
This is the same bug as Django had (CVE-2013-1443).
Details
A long password can cause a DoS because it is not using cached HMAC, length limits, or pre-hashing passwords longer than the block size of the hash function as per HMAC spec. This line of code hashes the full password each iteration: https://github.com/browserify/pbkdf2/blob/1c3b1f526b052a29b3b42120c9821895772df7e8/lib/sync.js#L60
Also see https://github.com/browserify/pbkdf2/issues/82
PoC
The first key will take a lot longer to generate when not using the native code and uses code from /lib/sync.js (ie when this if statement is true):
https://github.com/browserify/pbkdf2/blob/1c3b1f526b052a29b3b42120c9821895772df7e8/index.js#L33-L37
var pbkdf2 = require('pbkdf2'); var createHash = require('create-hash'); var pw = ".".repeat(1048576); // 1 MiB var t0 = performance.now(); var key1 = pbkdf2.pbkdf2Sync(pw, "salt", 1000, 32, "sha256"); var t1 = performance.now(); pw = createHash('sha256').update(pw).digest(); // HMAC specification for keys larger than block size...
Impact
DoS
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 12 | - | ||
debian 13 | - | ||
debian 14 | 3.1.7+~3.1.2-1 | ||
npm | 3.1.7 |
Aliases
References