Out-of-bounds write in Node.js - CVE-2018-12115
Published: August 22, 2018 / Updated: August 23, 2018
Vulnerability details
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability exists due to an out-of-bounds write condition in the Buffer component when used with UCS-2 encoding. A local attacker can cause a targeted system to stop functioning or execute arbitrary code with elevated privileges.
Affected software
Gentoo Linux
Opensuse
nodejs (Alpine package)
rh-nodejs6-nodejs (Red Hat package)
rh-nodejs8-nodejs (Red Hat package)
Red Hat Openshift Application Runtimes
How to mitigate CVE-2018-12115
nodejs (Alpine package) - update to 8.11.4-r0
rh-nodejs6-nodejs (Red Hat package) - addressed in versions 6.11.3-6.el6, 6.11.3-7.el7
rh-nodejs8-nodejs (Red Hat package) - update to 8.11.4-1.el7
External References
Related Security Bulletins
- Multiple vulnerabilities in Node.js
- Red Hat update for Node.js
- Red Hat update for Node.js
- OpenSUSE Linux update for nodejs4
- OpenSUSE Linux update for nodejs8
- OpenSUSE Linux update for nodejs6
- Gentoo update for Node.js
- Out-of-bounds write in nodejs (Alpine package)
- Red Hat Software Collections update for rh-nodejs6-nodejs
- Red Hat Software Collections update for rh-nodejs8-nodejs