Vulnerability Description
The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nodejs | Node.Js | <= 0.10.18 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/60026
- http://secunia.com/advisories/62170
- http://www-01.ibm.com/support/docview.wss?uid=swg21685987
- http://www-01.ibm.com/support/docview.wss?uid=swg21687263
- http://www-01.ibm.com/support/docview.wss?uid=swg21687928
- https://access.redhat.com/errata/RHSA-2016:1380
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96729
- https://github.com/raymondfeng/node-querystring/commit/43a604b7847e56bba49d0ce3ePatch
- https://github.com/visionmedia/node-querystring/issues/104
- https://nodesecurity.io/advisories/qs_dos_memory_exhaustion
- http://secunia.com/advisories/60026
- http://secunia.com/advisories/62170
- http://www-01.ibm.com/support/docview.wss?uid=swg21685987
- http://www-01.ibm.com/support/docview.wss?uid=swg21687263
- http://www-01.ibm.com/support/docview.wss?uid=swg21687928
FAQ
What is CVE-2014-7191?
CVE-2014-7191 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to...
How severe is CVE-2014-7191?
CVE-2014-7191 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-7191?
Check the references section above for vendor advisories and patch information. Affected products include: Nodejs Node.Js.