First published: Tue Jun 02 2020(Updated: )
A flaw was found in nodejs. Calling napi_get_value_string_latin1(), napi_get_value_string_utf8(), or napi_get_value_string_utf16() with a non-NULL buf, and a bufsize of 0 will cause the entire string value to be written to buf, probably overrunning the length of the buffer.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-nodejs12-nodejs | <0:12.18.2-1.el7 | 0:12.18.2-1.el7 |
redhat/rh-nodejs10-nodejs | <0:10.21.0-3.el7 | 0:10.21.0-3.el7 |
redhat/nodejs | <10.21.0 | 10.21.0 |
redhat/nodejs | <12.18.0 | 12.18.0 |
redhat/nodejs | <14.4.0 | 14.4.0 |
Nodejs Node.js | <10.21.0 | |
Nodejs Node.js | >=12.0.0<12.18.0 | |
Nodejs Node.js | >=14.0.0<14.4.0 | |
Oracle Banking Extensibility Workbench | =14.3.0 | |
Oracle Banking Extensibility Workbench | =14.4.0 | |
Oracle Blockchain Platform | <21.1.2 | |
Oracle MySQL Cluster | <=7.3.30 | |
Oracle MySQL Cluster | >=7.4.0<=7.4.29 | |
Oracle MySQL Cluster | >=7.5.0<=7.5.19 | |
Oracle MySQL Cluster | >=7.6.0<=7.6.15 | |
Oracle MySQL Cluster | >=8.0.0<=8.0.21 | |
Oracle Retail Xstore Point of Service | =16.0.6 | |
Oracle Retail Xstore Point of Service | =17.0.4 | |
Oracle Retail Xstore Point of Service | =18.0.3 | |
Oracle Retail Xstore Point of Service | =19.0.2 | |
Oracle Retail Xstore Point of Service | =20.0.1 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Active Iq Unified Manager Windows | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
Netapp Snapcenter | ||
debian/nodejs | 12.22.12~dfsg-1~deb11u4 12.22.12~dfsg-1~deb11u5 18.19.0+dfsg-6~deb12u2 18.19.0+dfsg-6~deb12u1 20.17.0+dfsg-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-8174 is a vulnerability found in nodejs that allows various kinds of memory corruption.
Calling certain functions with a non-NULL buf and bufsize of 0 can cause a buffer overrun.
CVE-2020-8174 has a severity value of 8.1 (high).
Nodejs versions < 10.21.0, 12.18.0, and < 14.4.0 are affected by CVE-2020-8174.
Upgrade to version 10.21.0, 12.18.0, or 14.4.0 or later to fix CVE-2020-8174 in nodejs.