Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2018-7167
Description:Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron"), 8.x (LTS "Carbon"), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.
Test IDs: 1.3.6.1.4.1.25623.1.0.813470   1.3.6.1.4.1.25623.1.0.851816   1.3.6.1.4.1.25623.1.0.813479   1.3.6.1.4.1.25623.1.1.4.2018.1892.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2018-7167
BugTraq ID: 106363
http://www.securityfocus.com/bid/106363
https://security.gentoo.org/glsa/202003-48




© 1998-2025 E-Soft Inc. All rights reserved.