VDB
Sign up
MEDIUM

GHSA-wrw9-m778-g6mc

Memory Exposure in bl

Quick fix

GHSA-wrw9-m778-g6mc — bl: upgrade to the fixed version with the command below.

npm install bl@0.9.5

Details

Versions of `bl` before 0.9.5 and 1.0.1 are vulnerable to memory exposure.

`bl.append(number)` in the affected `bl` versions passes a number to Buffer constructor, appending a chunk of uninitialized memory

## Recommendation

Update to version 0.9.5, 1.0.1 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bl
Introduced in: 0Fixed in: 0.9.5
Fixnpm install bl@0.9.5
npm/bl
Introduced in: 1.0.0Fixed in: 1.0.1
Fixnpm install bl@1.0.1

References