CVE-2018-7164

Severity
7.5HIGH
EPSS
1.1%
top 22.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 13

Description

Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDnodejs/node.js9.7.09.11.2+1
Debiannodejs< 10.15.0~dfsg-6+3
CVEListV5the_node.js_project/node.js10.x+, 9.7.X++1

🔴Vulnerability Details

3
GHSA
GHSA-32gr-2v7q-xgqj: Node2022-05-13
CVEList
CVE-2018-7164: Node2018-06-13
OSV
CVE-2018-7164: Node2018-06-13

📋Vendor Advisories

3
Microsoft
Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net2018-06-12
Red Hat
nodejs: uncontrolled memory consumption when using the net.Socket as a stream2018-06-12
Debian
CVE-2018-7164: nodejs - Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MED...2018

💬Community

2
Bugzilla
CVE-2018-7164 nodejs: uncontrolled memory consumption when using the net.Socket as a stream [epel-all]2018-06-13
Bugzilla
CVE-2018-7164 nodejs: uncontrolled memory consumption when using the net.Socket as a stream2018-06-13