NodeJS/dns-packet/5.0.0
An abstract-encoding compliant module for encoding / decoding DNS packets
https://www.npmjs.com/package/dns-packet
MIT
1 Security Vulnerabilities
Potential memory exposure in dns-packet
Published date: 2021-05-24T19:51:04Z
CVE: CVE-2021-23386
Links:
- https://nvd.nist.gov/vuln/detail/CVE-2021-23386
- https://github.com/advisories/GHSA-3wcq-x3mq-6r9p
- https://github.com/mafintosh/dns-packet/commit/25f15dd0fedc53688b25fd053ebbdffe3d5c1c56
- https://hackerone.com/bugs?subject=user&%3Breport_id=968858
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1295719
- https://snyk.io/vuln/SNYK-JS-DNSPACKET-1293563
- https://github.com/mafintosh/dns-packet/commit/0d0d593f8df4e2712c43957a6c62e95047f12b2d
This affects the package dns-packet before versions 1.3.2 and 5.2.2. It creates buffers with allocUnsafe and does not always fill them before forming network packets. This can expose internal application memory over unencrypted network when querying crafted invalid domain names.
Affected versions:
["2.0.0", "3.0.0", "3.0.1", "4.0.0", "4.1.0", "4.1.1", "4.2.0", "5.0.0", "5.0.1", "5.0.2", "5.0.3", "5.0.4", "5.1.0", "5.1.1", "5.1.2", "5.2.0", "5.2.1", "1.0.0", "1.0.1", "1.0.2", "1.1.0", "1.1.1", "1.2.0", "1.2.1", "1.2.2", "1.3.0", "1.3.1"]
Secure versions:
[5.2.2, 1.3.2, 1.3.3, 5.2.3, 5.2.4, 1.3.4, 5.3.0, 5.3.1, 5.4.0, 5.5.0, 5.6.0, 5.6.1]
Recommendation:
Update to version 5.6.1.
39 Other Versions
Version | License | Security | Released | |
---|---|---|---|---|
5.6.1 | MIT | 2023-08-25 - 11:00 | over 1 year | |
5.6.0 | MIT | 2023-04-18 - 10:56 | about 2 years | |
5.5.0 | MIT | 2023-03-27 - 10:25 | about 2 years | |
5.4.0 | MIT | 2022-06-14 - 21:13 | almost 3 years | |
5.3.1 | MIT | 2021-12-23 - 10:46 | over 3 years | |
5.3.0 | MIT | 2021-07-05 - 10:14 | almost 4 years | |
5.2.4 | MIT | 2021-05-26 - 09:26 | almost 4 years | |
5.2.3 | MIT | 2021-05-25 - 11:30 | almost 4 years | |
5.2.2 | MIT | 2021-05-19 - 17:59 | almost 4 years | |
5.2.1 | MIT | 1 | 2019-03-26 - 12:26 | about 6 years |
5.2.0 | MIT | 1 | 2019-02-21 - 22:34 | about 6 years |
5.1.2 | MIT | 1 | 2019-01-22 - 23:17 | over 6 years |
5.1.1 | MIT | 1 | 2019-01-22 - 21:52 | over 6 years |
5.1.0 | MIT | 1 | 2019-01-22 - 21:41 | over 6 years |
5.0.4 | MIT | 1 | 2018-10-16 - 16:15 | over 6 years |
5.0.3 | MIT | 1 | 2018-09-05 - 17:02 | over 6 years |
5.0.2 | MIT | 1 | 2018-07-24 - 17:54 | almost 7 years |
5.0.1 | MIT | 1 | 2018-07-02 - 19:52 | almost 7 years |
5.0.0 | MIT | 1 | 2018-06-01 - 07:34 | almost 7 years |
4.2.0 | MIT | 1 | 2018-04-04 - 15:13 | about 7 years |
4.1.1 | MIT | 1 | 2018-03-27 - 20:30 | about 7 years |
4.1.0 | MIT | 1 | 2018-02-11 - 10:09 | about 7 years |
4.0.0 | MIT | 1 | 2018-02-04 - 20:12 | over 7 years |
3.0.1 | MIT | 1 | 2018-01-14 - 09:25 | over 7 years |
3.0.0 | MIT | 1 | 2018-01-14 - 09:17 | over 7 years |
2.0.0 | MIT | 1 | 2018-01-11 - 20:38 | over 7 years |
1.3.4 | MIT | 2021-05-26 - 09:28 | almost 4 years | |
1.3.3 | MIT | 2021-05-25 - 11:29 | almost 4 years | |
1.3.2 | MIT | 2021-05-25 - 08:35 | almost 4 years | |
1.3.1 | MIT | 1 | 2018-01-11 - 20:22 | over 7 years |
1.3.0 | MIT | 1 | 2018-01-10 - 18:43 | over 7 years |
1.2.2 | MIT | 1 | 2017-08-16 - 10:35 | over 7 years |
1.2.1 | MIT | 1 | 2017-08-12 - 20:20 | over 7 years |
1.2.0 | MIT | 1 | 2017-08-12 - 16:42 | over 7 years |
1.1.1 | MIT | 1 | 2016-11-11 - 04:27 | over 8 years |
1.1.0 | MIT | 1 | 2016-02-23 - 01:37 | about 9 years |
1.0.2 | MIT | 1 | 2016-02-18 - 21:21 | about 9 years |
1.0.1 | MIT | 1 | 2016-02-18 - 21:16 | about 9 years |
1.0.0 | MIT | 1 | 2016-02-18 - 20:51 | about 9 years |