CVE-2022-25345
HIGH7.5EPSS 0.43%Uncontrolled Resource Consumption in @discordjs/opus
發布日:2022/6/18修改日:2025/12/3
描述
All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.
受影響套件(2)
- Alpine/opusfrom 0, < 0
- npm/@discordjs/opusfrom 0, < 0.8.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
參考連結(7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-25345
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2022-25345
- PATCHhttps://github.com/discordjs/opus
- WEBhttps://github.com/discordjs/opus/blob/3ca4341ffdd81cf83cec57045e59e228e6017590/src/node-opus.cc#L28
- WEBhttps://github.com/discordjs/opus/commit/406249f3fca484a2af97a34ceb989019efa09bc7
- WEBhttps://github.com/discordjs/opus/releases/tag/v0.8.0
- WEBhttps://snyk.io/vuln/SNYK-JS-DISCORDJSOPUS-2403100