CVE-2018-3738: Medium severity @protobufjs/codegen vulnerability
Published Jun 7, 2018
·Updated
protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.
Affected Software
1 affected component
Protobufjs Project Protobufjs Node.js<=6.8.5
Event History
Jun 7, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-3738?
The severity of CVE-2018-3738 has been classified as high due to its potential for ReDoS attacks.
2
How do I fix CVE-2018-3738?
To fix CVE-2018-3738, update protobufjs to version 6.9.0 or later, which addresses the ReDoS vulnerability.
3
What kind of attack does CVE-2018-3738 allow?
CVE-2018-3738 allows for regular expression denial of service (ReDoS) attacks when parsing malicious .proto files.
4
Which versions of protobufjs are affected by CVE-2018-3738?
CVE-2018-3738 affects protobufjs versions up to and including 6.8.5.
5
Is CVE-2018-3738 related to specific software?
Yes, CVE-2018-3738 specifically affects the protobufjs library used in Node.js applications.