CVE-2018-7164

Related Vulnerabilities: CVE-2018-7164  

Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour.

The MITRE CVE dictionary describes this issue as:

Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour.

Find out more about CVE-2018-7164 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 7.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact High

Affected Packages State

Platform Package State
Red Hat Software Collections for Red Hat Enterprise Linux rh-nodejs6-nodejs Not affected
Red Hat Software Collections for Red Hat Enterprise Linux rh-nodejs8-nodejs Not affected
Red Hat Software Collections for Red Hat Enterprise Linux rh-nodejs4-nodejs Not affected
Red Hat OpenShift Container Platform 3.10 logging-kibana Not affected
Red Hat OpenShift Container Platform 3.10 logging-auth-proxy Not affected
Red Hat OpenShift Application Runtimes 1.0 rhoar-nodejs Not affected