Description
All versions of the package node-stringbuilder are vulnerable to Out-of-bounds Read due to incorrect memory length calculation, by calling ToBuffer, ToString, or CharAt on a StringBuilder object with a non-empty string value input. It's possible to return previously allocated memory, for example, by providing negative indexes, leading to an Information Disclosure.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2343 | All versions of the package node-stringbuilder are vulnerable to Out-of-bounds Read due to incorrect memory length calculation, by calling ToBuffer, ToString, or CharAt on a StringBuilder object with a non-empty string value input. It's possible to return previously allocated memory, for example, by providing negative indexes, leading to an Information Disclosure. |
Github GHSA |
GHSA-g533-xq5w-jmf3 | node-stringbuilder vulnerable to Out-of-bounds Read |
References
History
Mon, 09 Sep 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Magiclen
Magiclen stringbuilder |
|
| CPEs | cpe:2.3:a:magiclen:stringbuilder:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Magiclen
Magiclen stringbuilder |
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-08-01T22:27:34.821Z
Reserved: 2023-12-22T12:33:20.122Z
Link: CVE-2024-21524
Updated: 2024-08-01T22:27:34.821Z
Status : Modified
Published: 2024-07-10T05:15:11.340
Modified: 2024-11-21T08:54:37.010
Link: CVE-2024-21524
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA