CVE-2019-10196
published 2021-03-19CVE-2019-10196: A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper…
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.39%
69.5th percentile
A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| graphviz | graphviz | >= 0 < 2.36.0-0ubuntu3.2+esm1 | 2.36.0-0ubuntu3.2+esm1 |
| graphviz | graphviz | >= 0 < 2.38.0-12ubuntu2.1+esm1 | 2.38.0-12ubuntu2.1+esm1 |
| graphviz | graphviz | >= 0 < 2.40.1-2ubuntu0.1~esm1 | 2.40.1-2ubuntu0.1~esm1 |
| graphviz | graphviz | >= 0 < 2.42.2-3ubuntu0.1~esm1 | 2.42.2-3ubuntu0.1~esm1 |
| http-proxy-agent_project | http-proxy-agent | < 2.1.0 | 2.1.0 |
| http-proxy-agent_project | http-proxy-agent | >= 0 < 2.1.0 | 2.1.0 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:N/C:P/I:P/A:C
osv5.5MEDIUM
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
graphviz vulnerabilities
osv·2023-03-24·CVSS 5.5
CVE-2018-10196 graphviz vulnerabilities
graphviz vulnerabilities
It was discovered that graphviz contains null pointer dereference
vulnerabilities. Exploitation via a specially crafted input file can cause
a denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-10196)
It was discovered that graphviz contains null pointer dereference
vulnerabilities. Exploitation via a specially crafted input file can cause
a denial of service. These issues only affected Ubuntu 14.04 ESM and Ubuntu
18.04 LTS. (CVE-2019-11023)
It was discovered that graphviz contains a buffer overflow vulnerability.
Exploitation via a specially crafted input file can cause a denial of
service or possibly allow for arbitrary code execution. These issues only
affected Ubuntu 14.04 ESM, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2020-18032)
OSV
graphviz vulnerabilities
osv·2022-02-03·CVSS 5.5
CVE-2018-10196 graphviz vulnerabilities
graphviz vulnerabilities
It was discovered that graphviz contains null pointer dereference
vulnerabilities. Exploitation via a specially crafted input file
can cause a denial of service.
(CVE-2018-10196, CVE-2019-11023)
It was discovered that graphviz contains a buffer overflow
vulnerability. Exploitation via a specially crafted input file can cause
a denial of service or possibly allow for arbitrary code execution.
(CVE-2020-18032)
GHSA
Resource Exhaustion Denial of Service in http-proxy-agent
ghsa·2022-01-06
CVE-2019-10196 [MEDIUM] CWE-665 Resource Exhaustion Denial of Service in http-proxy-agent
Resource Exhaustion Denial of Service in http-proxy-agent
A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter.
OSV
Resource Exhaustion Denial of Service in http-proxy-agent
osv·2022-01-06
CVE-2019-10196 [MEDIUM] Resource Exhaustion Denial of Service in http-proxy-agent
Resource Exhaustion Denial of Service in http-proxy-agent
A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter.
Red Hat
nodejs-http-proxy-agent: Denial of Service and data leak due to improper buffer sanitization
vendor_redhat·2018-04-05·CVSS 9.8
CVE-2019-10196 [CRITICAL] CWE-665 nodejs-http-proxy-agent: Denial of Service and data leak due to improper buffer sanitization
nodejs-http-proxy-agent: Denial of Service and data leak due to improper buffer sanitization
A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter.
A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized mem
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10196 nodejs-http-proxy-agent: Denial of Service and data leak due to improper buffer sanitization
bugzilla·2018-04-13·CVSS 9.1
CVE-2019-10196 [CRITICAL] CVE-2019-10196 nodejs-http-proxy-agent: Denial of Service and data leak due to improper buffer sanitization
CVE-2019-10196 nodejs-http-proxy-agent: Denial of Service and data leak due to improper buffer sanitization
A flaw was found in http-proxy-agent versions before 2.1.0. The http-proxy-agent passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON).
References:
https://hackerone.com/reports/321631
Patch:
https://github.com/TooTallNate/node-http-proxy-agent/commit/b7b7cc793c3226aa83f820ce5c277e81862d32eb
Discussion:
Created nodejs-http-proxy-agent tracking bugs for this issue:
Affects: fedora-all [bug 1567247]
Affects: epel-7 [bug 1567246]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not
Bugzilla
CVE-2019-10196 nodejs-http-proxy-agent: Denial of Service and data leak due to improper buffer sanitization [epel-7]
bugzilla·2018-04-13·CVSS 9.8
CVE-2019-10196 [CRITICAL] CVE-2019-10196 nodejs-http-proxy-agent: Denial of Service and data leak due to improper buffer sanitization [epel-7]
CVE-2019-10196 nodejs-http-proxy-agent: Denial of Service and data leak due to improper buffer sanitization [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use
Bugzilla
CVE-2019-10196 nodejs-http-proxy-agent: Denial of Service and data leak due to improper buffer sanitization [fedora-all]
bugzilla·2018-04-13·CVSS 9.8
CVE-2019-10196 [CRITICAL] CVE-2019-10196 nodejs-http-proxy-agent: Denial of Service and data leak due to improper buffer sanitization [fedora-all]
CVE-2019-10196 nodejs-http-proxy-agent: Denial of Service and data leak due to improper buffer sanitization [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: thi
2021-03-19
Published