Resource management error in Node.js - CVE-2020-8277

 

Resource management error in Node.js - CVE-2020-8277

Published: November 19, 2020 / Updated: November 21, 2020


Vulnerability identifier: #VU48569
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8277
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application when processing a large number of DNS responses. A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a denial of service condition.


Affected software

Node.js
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
openEuler
Ubuntu
Fedora
IBM Cloud Transformation Advisor
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Cloud Automation Manager
BIG-IQ Centralized Management
MySQL Cluster
BIG-IP Advanced WAF
BIG-IP PEM
BIG-IP Analytics
BIG-IP GTM
BIG-IP APM
BIG-IP FPS
BIG-IP ASM
BIG-IP LTM
BIG-IP AFM
BIG-IP Link Controller
BIG-IP DNS
BIG-IP AAM
Dell EMC VxRail Appliance
BIG-IP
BIG-IP DDHD
BIG-IP SSLO
nodejs-current (Alpine package)
nodejs (Alpine package)
libc-ares2 (Ubuntu package)
c-ares-help
c-ares-debuginfo
c-ares-devel
c-ares-debugsource
c-ares
mingw-c-ares
rh-nodejs12-nodejs (Red Hat package)
rh-nodejs14-nodejs (Red Hat package)
Oracle Retail Xstore Point of Service
Storage Defender – Data Protect
Oracle GraalVM Enterprise Edition

How to mitigate CVE-2020-8277

Install updates from vendor's website.

Node.js - addressed in versions 12.19.1, 14.15.1, 15.2.1
MySQL Cluster - update to 8.0.24
nodejs-current (Alpine package) - update to 15.3.0-r0
nodejs (Alpine package) - update to 14.15.1-r0
Storage Defender – Data Protect - update to 1.4.0
libc-ares2 (Ubuntu package) - update to 1.16.1-1ubuntu0.1
c-ares-help - update to 1.16.1-3
c-ares-debuginfo - update to 1.16.1-3
c-ares-devel - update to 1.16.1-3
c-ares-debugsource - update to 1.16.1-3
c-ares - update to 1.16.1-3
c-ares - addressed in versions 1.17.0-1.fc32, 1.17.0-1.fc33
mingw-c-ares - addressed in versions 1.17.1-1.fc32, 1.17.1-1.fc33
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.0.0
IBM Cloud Automation Manager - update to 4.2.0.1 iFix 2
Dell EMC VxRail Appliance - update to 7.0.240
rh-nodejs12-nodejs (Red Hat package) - update to 12.19.1-2.el7
rh-nodejs14-nodejs (Red Hat package) - update to 14.15.4-2.el7

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins