CVE-2015-5380

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:google:v8:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:iojs:io.js:*:*:*:*:*:*:*:*
cpe:2.3:a:iojs:io.js:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:iojs:io.js:2.3.2:*:*:*:*:*:*:*
cpe:2.3:a:iojs:io.js:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:iojs:io.js:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*
cpe:2.3:a:iojs:io.js:2.3.0:*:*:*:*:*:*:*
cpe:2.3:a:iojs:io.js:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:iojs:io.js:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:iojs:io.js:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:iojs:io.js:2.1.0:*:*:*:*:*:*:*

Information

Published : 2015-07-09 03:59

Updated : 2016-11-28 11:33


NVD link : CVE-2015-5380

Mitre link : CVE-2015-5380


JSON object : View

CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

Advertisement

dedicated server usa

Products Affected

nodejs

  • node.js

google

  • v8

iojs

  • io.js