CRITICAL
GHSA-q5pq-pgrv-fh89
dns-sync command injection vulnerability
Quick fix
GHSA-q5pq-pgrv-fh89 — dns-sync: upgrade to the fixed version with the command below.
npm install dns-sync@0.1.1Details
The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2014-9682[ADVISORY]
- https://github.com/skoranga/node-dns-sync/issues/1[WEB]
- https://github.com/skoranga/node-dns-sync/commit/d9abaae384b198db1095735ad9c1c73d7b890a0d[WEB]
- https://github.com/advisories/GHSA-q5pq-pgrv-fh89[ADVISORY]
- https://github.com/skoranga/node-dns-sync[PACKAGE]
- http://www.openwall.com/lists/oss-security/2014/11/11/6[WEB]