#VU13894 Memory corruption in atob - CVE-2018-3745
Published: July 16, 2018 / Updated: July 17, 2018
atob
npm Inc.
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information or cause DoS condition on the target system.
The vulnerability exists due to boundary error when a number is passed from user-supplied JSON-encoded input. A remote unauthenticated attacker can send a specially crafted request that submits malicious input, trigger memory corruption and access sensitive, uninitialized memory or consume excessive amounts of memory resources, resulting in a DoS condition.