Buffer overflow in Node.js - CVE-2020-8174

 

Buffer overflow in Node.js - CVE-2020-8174

Published: June 3, 2020


Vulnerability identifier: #VU28539
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8174
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within napi_get_value_string_latin1(), napi_get_value_string_utf8(), or napi_get_value_string_utf16() functions. A remote attacker can create a specially crafted data to the application, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Node.js
Gentoo Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Opensuse
Ubuntu
MicroSCADA X SYS600
MicroSCADA Pro SYS600
Gateway Station (GWS)
e-mesh EMS
FACTS Control Platform (FCP)
IBM Cloud Transformation Advisor
IBM Cloud Pak for Business Automation
Oracle Blockchain Platform
nodejs (Alpine package)
nodejs (Debian package)
rh-nodejs10-nodejs (Red Hat package)
nodejs-current (Alpine package)
nodejs-legacy (Ubuntu package)
nodejs-dev (Ubuntu package)
nodejs (Ubuntu package)
libnode-dev (Ubuntu package)
libnode64 (Ubuntu package)
rh-nodejs12-nodejs (Red Hat package)
MySQL Cluster
Oracle Banking Extensibility Workbench
Red Hat OpenShift Container Platform

How to mitigate CVE-2020-8174

Install updates from vendor's website.

Node.js - addressed in versions 10.21.0, 12.18.0, 14.4.0
MicroSCADA X SYS600 - update to 10.3
MicroSCADA Pro SYS600 - update to 10.3
e-mesh EMS - update to 1.0.1
nodejs (Alpine package) - update to 12.18.3-r0
MySQL Cluster - addressed in versions 7.3.31, 7.5.20, 7.6.16, 8.0.22
nodejs (Debian package) - update to 10.21.0~dfsg-1~deb10u1
rh-nodejs10-nodejs (Red Hat package) - update to 10.21.0-3.el7
nodejs-current (Alpine package) - update to 14.4.0-r0
IBM Cloud Pak for Business Automation - update to 20.0.2 ifix 001
nodejs-legacy (Ubuntu package) - update to Ubuntu Pro
nodejs-dev (Ubuntu package) - update to Ubuntu Pro
nodejs (Ubuntu package) - addressed in versions Ubuntu Pro, 10.19.0~dfsg-3ubuntu1.1
Red Hat OpenShift Container Platform - update to 4.5.8
libnode-dev (Ubuntu package) - update to 10.19.0~dfsg-3ubuntu1.1
libnode64 (Ubuntu package) - update to 10.19.0~dfsg-3ubuntu1.1
rh-nodejs12-nodejs (Red Hat package) - update to 12.18.2-1.el7
Oracle Blockchain Platform - update to 21.1.2

External References

Related Security Bulletins