CVE-2017-14919: Input Validation
Published Oct 30, 2017
·Updated
Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.
Affected Software
23 affected components
Nodejs Node.js=4.8.2
Nodejs Node.js=4.8.3
Nodejs Node.js=4.8.4
Nodejs Node.js=6.10.2
Nodejs Node.js=6.10.3
Nodejs Node.js=6.11.0
Nodejs Node.js=6.11.1
Nodejs Node.js=6.11.2
Nodejs Node.js=6.11.3
Nodejs Node.js=6.11.4
Nodejs Node.js=8.0.0
Nodejs Node.js=8.1.0
Nodejs Node.js=8.1.1
Nodejs Node.js=8.1.2
Nodejs Node.js=8.1.3
Nodejs Node.js=8.1.4
Nodejs Node.js=8.2.0
Nodejs Node.js=8.2.1
Nodejs Node.js=8.3.0
Nodejs Node.js=8.4.0
Nodejs Node.js=8.5.0
Nodejs Node.js=8.6.0
Nodejs Node.js=8.7.0
Event History
Oct 30, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-14919?
CVE-2017-14919 has a severity rating of high due to its potential to cause a denial of service.
2
How do I fix CVE-2017-14919?
To fix CVE-2017-14919, upgrade Node.js to version 4.8.5, 6.11.5, or 8.8.0 or later.
3
Which versions of Node.js are affected by CVE-2017-14919?
CVE-2017-14919 affects Node.js versions 4.8.2 to 4.8.4, 6.x before 6.11.5, and 8.x before 8.8.0.
4
Is CVE-2017-14919 a remote vulnerability?
Yes, CVE-2017-14919 allows remote attackers to exploit the vulnerability.
5
What type of attack does CVE-2017-14919 enable?
CVE-2017-14919 enables attackers to cause a denial of service through uncaught exceptions leading to crashes.