First published: Mon Jan 23 2017(Updated: )
The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Vercel Ms | <0.7.1 | |
npm/ms | <0.7.1 | 0.7.1 |
<0.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8315 is a vulnerability in the Node.js ms package which allows attackers to cause a denial of service by exploiting a regular expression implementation error.
CVE-2015-8315 has a severity rating of 7.5 (high).
The ms package before version 0.7.1 for Node.js is affected by CVE-2015-8315.
An attacker can exploit CVE-2015-8315 by using a regular expression to cause the application to hang.
Yes, you can find references for CVE-2015-8315 at the following URLs: [https://exchange.xforce.ibmcloud.com/vulnerabilities/112567](https://exchange.xforce.ibmcloud.com/vulnerabilities/112567), [https://www.ibm.com/support/pages/node/6214472](https://www.ibm.com/support/pages/node/6214472), [http://www.openwall.com/lists/oss-security/2016/04/20/11](http://www.openwall.com/lists/oss-security/2016/04/20/11).