CVE-2018-7167
7.5
HIGH
CVSS 3.1
EPSS 0.76%
Description
Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron"), 8.x (LTS "Carbon"), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.
How to fix CVE-2018-7167
To remediate CVE-2018-7167, upgrade the affected package to a fixed version below.
- —upgrade to 8.11.3-r0 or later
- —upgrade to 10.15.0~dfsg-6 or later
Is CVE-2018-7167 being exploited?
Low — EPSS is 0.8%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 8.11.3-r0
- from 0, < 10.15.0~dfsg-6
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |