MEDIUM5.3
GHSA-hmqg-p8f8-3qrw
Out-of-bounds Read in fast-string-search
Details
All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and length calculation for any non-string input as the source. This allows the attacker to read previously allocated memory.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/fast-string-search
Introduced in:
0No fixed version published yet for fast-string-search (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-25872[ADVISORY]
- https://github.com/magiclen/node-fast-string-search[PACKAGE]
- https://github.com/magiclen/node-fast-string-search/blob/c8dd9fc966abc80b327f509e63360f59e0de9fb5/src/fast-string-search.c%23L192[WEB]
- https://snyk.io/vuln/SNYK-JS-FASTSTRINGSEARCH-2392368[WEB]