CVE-2015-8854
published 2017-01-23CVE-2015-8854: The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trigger a…
PriorityP432high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.33%
90.1th percentile
The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trigger a "catastrophic backtracking issue for the em inline rule," aka a "regular expression denial of service (ReDoS)."
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-marked | < node-marked 0.3.6+dfsg-1 (bookworm) | node-marked 0.3.6+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| marked_project | marked | < 0.3.4 | 0.3.4 |
| marked_project | marked | >= 0 < 0.3.4 | 0.3.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2015-8854: node-marked - The marked package before 0.3.4 for Node.js allows attackers to cause a denial o...
vendor_debian·2015·CVSS 7.5
CVE-2015-8854 [HIGH] CVE-2015-8854: node-marked - The marked package before 0.3.4 for Node.js allows attackers to cause a denial o...
The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trigger a "catastrophic backtracking issue for the em inline rule," aka a "regular expression denial of service (ReDoS)."
Scope: local
bookworm: resolved (fixed in 0.3.6+dfsg-1)
bullseye: resolved (fixed in 0.3.6+dfsg-1)
forky: resolved (fixed in 0.3.6+dfsg-1)
sid: resolved (fixed in 0.3.6+dfsg-1)
trixie: resolved (fixed in 0.3.6+dfsg-1)
OSV
Regular Expression Denial of Service in marked
osv·2017-10-24
CVE-2015-8854 [HIGH] Regular Expression Denial of Service in marked
Regular Expression Denial of Service in marked
Versions 0.3.3 and earlier of `marked` are affected by a regular expression denial of service ( ReDoS ) vulnerability when passed inputs that reach the `em` inline rule.
## Recommendation
Update to version 0.3.4 or later.
GHSA
Regular Expression Denial of Service in marked
ghsa·2017-10-24
CVE-2015-8854 [HIGH] CWE-1333 Regular Expression Denial of Service in marked
Regular Expression Denial of Service in marked
Versions 0.3.3 and earlier of `marked` are affected by a regular expression denial of service ( ReDoS ) vulnerability when passed inputs that reach the `em` inline rule.
## Recommendation
Update to version 0.3.4 or later.
OSV
CVE-2015-8854: The marked package before 0
osv·2017-01-23·CVSS 7.5
CVE-2015-8854 [HIGH] CVE-2015-8854: The marked package before 0
The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trigger a "catastrophic backtracking issue for the em inline rule," aka a "regular expression denial of service (ReDoS)."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8854 marked: regular expression denial of service [epel-6]
bugzilla·2016-04-22·CVSS 7.5
CVE-2015-8854 [HIGH] CVE-2015-8854 marked: regular expression denial of service [epel-6]
CVE-2015-8854 marked: regular expression denial of service [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Discussio
Bugzilla
CVE-2015-8854 marked: regular expression denial of service
bugzilla·2016-04-22·CVSS 7.5
CVE-2015-8854 [HIGH] CVE-2015-8854 marked: regular expression denial of service
CVE-2015-8854 marked: regular expression denial of service
Marked 0.3.3 and earlier is vulnerable to regular expression denial of service (ReDoS) when certain types of input are passed in to be parsed.
"The Regular expression Denial of Service (ReDoS) is a Denial of Service attack, that exploits the fact that most Regular Expression implementations may reach extreme situations that cause them to work very slowly (exponentially related to input size). An attacker can then cause a program using a Regular Expression to enter these extreme situations and then hang for a very long time."
External references:
https://nodesecurity.io/advisories/23
https://github.com/chjj/marked/issues/497
Discussion:
Created marked tracking bugs for this issue:
Affects: fedora-all [bug 1329534]
Affects: ep
Bugzilla
CVE-2015-8854 marked: regular expression denial of service [fedora-all]
bugzilla·2016-04-22·CVSS 7.5
CVE-2015-8854 [HIGH] CVE-2015-8854 marked: regular expression denial of service [fedora-all]
CVE-2015-8854 marked: regular expression denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora
Bugzilla
CVE-2015-8854 marked: regular expression denial of service [epel-7]
bugzilla·2016-04-22·CVSS 7.5
CVE-2015-8854 [HIGH] CVE-2015-8854 marked: regular expression denial of service [epel-7]
CVE-2015-8854 marked: regular expression denial of service [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Discussio
http://www.openwall.com/lists/oss-security/2016/04/20/11https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO2RMVVZVV6NFTU46B5RYRK7ZCXYARZS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M6BJG6RGDH7ZWVVAUFBFI5L32RSMQN2S/https://nodesecurity.io/advisories/23https://support.f5.com/csp/article/K05052081?utm_source=f5support&%3Butm_medium=RSShttp://www.openwall.com/lists/oss-security/2016/04/20/11https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO2RMVVZVV6NFTU46B5RYRK7ZCXYARZS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M6BJG6RGDH7ZWVVAUFBFI5L32RSMQN2S/https://nodesecurity.io/advisories/23https://support.f5.com/csp/article/K05052081?utm_source=f5support&%3Butm_medium=RSS
2017-01-23
Published