5
CVSSv2

CVE-2021-22918

Published: 12/07/2021 Updated: 16/01/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Node.js prior to 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nodejs node.js

siemens sinec infrastructure network services

Vendor Advisories

Debian Bug report logs - #990561 libuv1: CVE-2021-22918 Package: src:libuv1; Maintainer for src:libuv1 is Dominique Dumont <dod@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 2 Jul 2021 08:39:01 UTC Severity: grave Tags: security, upstream Found in version libuv1/1400-1 Reply or sub ...
An out-of-bounds read was discovered in the uv__idna_to_ascii() function of Libuv, an asynchronous event notification library, which could result in denial of service or information disclosure For the stable distribution (buster), this problem has been fixed in version 1241-1+deb10u1 We recommend that you upgrade your libuv1 packages For the d ...
Nodejs before 1641, 14172, 12222 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer This can lead to information disclosures or crashes This function can b ...
Nodejs before versions 1641, 14172 and 12222 is vulnerable to an out-of-bounds read in the libuv's uv__idna_toascii() function which is used to convert strings to ASCII This is called by Node's dns module's lookup() function and can lead to information disclosures or crashes ...

ICS Advisories

Siemens SINEC INS
Critical Infrastructure Sectors: Energy