CVE-2020-8244
published 2020-08-30CVE-2020-8244: A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it…
PriorityP335medium6.5CVSS 3.1
AVNACLPRNUINSUCLINAL
EPSS
2.18%
80.6th percentile
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bufferlist_project | bufferlist | < 1.2.3 | 1.2.3 |
| bufferlist_project | bufferlist | >= 2.0.0 < 2.2.1 | 2.2.1 |
| bufferlist_project | bufferlist | >= 3.0.0 < 3.0.1 | 3.0.1 |
| bufferlist_project | bufferlist | >= 4.0.0 < 4.0.3 | 4.0.3 |
| debian | debian_linux | — | — |
| debian | node-bl | < node-bl 4.0.3-1 (bookworm) | node-bl 4.0.3-1 (bookworm) |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Remote Memory Exposure in bl
osv·2020-09-02
CVE-2020-8244 [MEDIUM] Remote Memory Exposure in bl
Remote Memory Exposure in bl
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.
GHSA
Remote Memory Exposure in bl
ghsa·2020-09-02
CVE-2020-8244 [MEDIUM] CWE-125 Remote Memory Exposure in bl
Remote Memory Exposure in bl
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.
OSV
CVE-2020-8244: A buffer over-read vulnerability exists in bl <4
osv·2020-08-30·CVSS 6.5
CVE-2020-8244 [MEDIUM] CVE-2020-8244: A buffer over-read vulnerability exists in bl <4
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.
Ubuntu
bl vulnerability
vendor_ubuntu·2022-02-08
CVE-2020-8244 bl vulnerability
Title: bl vulnerability
Summary: bl could be made to crash if it received specially crafted input.
It was discovered that bl incorrectly handled certain inputs. An attacker
could possibly use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
bl vulnerability
vendor_ubuntu·2021-09-30
CVE-2020-8244 bl vulnerability
Title: bl vulnerability
Summary: node-bl could be made to expose sensitive information if it received specially
crafted input.
It was discovered that bl didn't properly sanitize the inputs. An attacker
could use this to leak sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
nodejs-bl: buffer over-read vulnerability leads to corrupted BufferList which can result in uninitialized memory being leaked
vendor_redhat·2020-08-30·CVSS 6.5
CVE-2020-8244 [MEDIUM] CWE-125 nodejs-bl: buffer over-read vulnerability leads to corrupted BufferList which can result in uninitialized memory being leaked
nodejs-bl: buffer over-read vulnerability leads to corrupted BufferList which can result in uninitialized memory being leaked
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.
Statement: Red Hat OpenShift Container Platform 4 delivers the kibana package where the nodejs-bl module is used, but during the update to container first (to openshift4/ose-logging-kibana6) the dependency was removed and hence kibana package is marked as wontfix. This may be fixed in the future.
Package: kibana (Red Hat OpenShift Container Pla
Debian
CVE-2020-8244: node-bl - A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3...
vendor_debian·2020·CVSS 6.5
CVE-2020-8244 [MEDIUM] CVE-2020-8244: node-bl - A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3...
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.
Scope: local
bookworm: resolved (fixed in 4.0.3-1)
bullseye: resolved (fixed in 4.0.3-1)
forky: resolved (fixed in 4.0.3-1)
sid: resolved (fixed in 4.0.3-1)
trixie: resolved (fixed in 4.0.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-8244 nodejs-bl: buffer over-read vulnerability leads to corrupted BufferList which can result in uninitialized memory being leaked [fedora-all]
bugzilla·2020-09-02·CVSS 6.5
CVE-2020-8244 [MEDIUM] CVE-2020-8244 nodejs-bl: buffer over-read vulnerability leads to corrupted BufferList which can result in uninitialized memory being leaked [fedora-all]
CVE-2020-8244 nodejs-bl: buffer over-read vulnerability leads to corrupted BufferList which can result in uninitialized memory being leaked [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
f
Bugzilla
CVE-2020-8244 nodejs-bl: buffer over-read vulnerability leads to corrupted BufferList which can result in uninitialized memory being leaked [epel-7]
bugzilla·2020-09-02·CVSS 6.5
CVE-2020-8244 [MEDIUM] CVE-2020-8244 nodejs-bl: buffer over-read vulnerability leads to corrupted BufferList which can result in uninitialized memory being leaked [epel-7]
CVE-2020-8244 nodejs-bl: buffer over-read vulnerability leads to corrupted BufferList which can result in uninitialized memory being leaked [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg co
Bugzilla
CVE-2020-8244 nodejs-bl: buffer over-read vulnerability leads to corrupted BufferList which can result in uninitialized memory being leaked
bugzilla·2020-09-02·CVSS 6.5
CVE-2020-8244 [MEDIUM] CVE-2020-8244 nodejs-bl: buffer over-read vulnerability leads to corrupted BufferList which can result in uninitialized memory being leaked
CVE-2020-8244 nodejs-bl: buffer over-read vulnerability leads to corrupted BufferList which can result in uninitialized memory being leaked
A buffer over-read vulnerability exists in bl AC:L
A:N -> A:L
Also I increased the Impact to Moderate.
---
Upstream fix: https://github.com/rvagg/bl/commit/d3e240e3b8ba4048d3c76ef5fb9dd1f8872d3190
---
Statement:
Red Hat OpenShift Container Platform 4 delivers the kibana package where the nodejs-bl module is used, but during the update to container first (to openshift4/ose-logging-kibana6) the dependency was removed and hence kibana package is marked as wontfix. This may be fixed in the future.
2020-08-30
Published