GHSA-mvc4-gp8c-r52fHighCVSS 7.5
Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a...
🔗 CVE IDs covered (1)
📋 Description
Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2017-14919
- http://www.securityfocus.com/bid/101881
- https://nodejs.org/en/blog/release/v4.8.5
- https://nodejs.org/en/blog/release/v6.11.5
- https://nodejs.org/en/blog/release/v8.8.0
- https://nodejs.org/en/blog/vulnerability/oct-2017-dos
- https://cert-portal.siemens.com/productcert/html/ssa-470355.html
- https://github.com/advisories/GHSA-mvc4-gp8c-r52f