CVE-2014-7191
EPSS 0.69%Denial-of-Service Memory Exhaustion in qs
發布日:2017/10/24修改日:2023/11/8
描述
Versions prior to 1.0 of `qs` are affected by a denial of service condition. This condition is triggered by parsing a crafted string that deserializes into very large sparse arrays, resulting in the process running out of memory and eventually crashing. ## Recommendation Update to version 1.0.0 or later.
受影響套件(2)
- Debian/node-qsfrom 0, < 2.2.4-1
- npm/qsfrom 0, < 1.0.0
參考連結(14)
- ADVISORYhttps://github.com/advisories/GHSA-jjv7-qpx3-h62q
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2014-7191
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2014-7191
- PATCHhttps://github.com/visionmedia/node-querystring
- WEBhttps://access.redhat.com/errata/RHSA-2016:1380
- WEBhttp://secunia.com/advisories/60026
- WEBhttp://secunia.com/advisories/62170
- WEBhttps://exchange.xforce.ibmcloud.com/vulnerabilities/96729
- WEBhttps://github.com/raymondfeng/node-querystring/commit/43a604b7847e56bba49d0ce3e222fe89569354d8
- WEBhttps://github.com/visionmedia/node-querystring/issues/104
- WEBhttps://www.npmjs.com/advisories/29
- WEBhttp://www-01.ibm.com/support/docview.wss?uid=swg21685987
- WEBhttp://www-01.ibm.com/support/docview.wss?uid=swg21687263
- WEBhttp://www-01.ibm.com/support/docview.wss?uid=swg21687928