{"id":"GHSA-86mr-6m89-vgj3","summary":"Buffer Overflow in node-weakauras-parser","details":"Affected versions of `node-weakauras-parser` are vulnerable to a Buffer Overflow. The `encode_weakaura` function fails to properly validate the input size. A buffer of 13835058055282163711 bytes causes an overflow on 64-bit systems.\n\n\n## Recommendation\n\nUpgrade to versions 1.0.5, 2.0.2, 3.0.1 or later.","modified":"2021-10-04T21:10:07Z","published":"2020-09-03T15:51:38Z","database_specific":{"cwe_ids":["CWE-120"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-08-31T19:01:42Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/Zireael-N/node-weakauras-parser/commit/bc146da09db689e554d28e948f1cf1c138f09f69#diff-023afe6291ac9ada88788108cb3367b3R38-R43"},{"type":"PACKAGE","url":"https://github.com/Zireael-N/node-weakauras-parser"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1504"}],"affected":[{"package":{"name":"node-weakauras-parser","ecosystem":"npm","purl":"pkg:npm/node-weakauras-parser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.4"},{"fixed":"1.0.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-86mr-6m89-vgj3/GHSA-86mr-6m89-vgj3.json"}},{"package":{"name":"node-weakauras-parser","ecosystem":"npm","purl":"pkg:npm/node-weakauras-parser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0"},{"fixed":"2.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-86mr-6m89-vgj3/GHSA-86mr-6m89-vgj3.json"}},{"package":{"name":"node-weakauras-parser","ecosystem":"npm","purl":"pkg:npm/node-weakauras-parser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-86mr-6m89-vgj3/GHSA-86mr-6m89-vgj3.json"}}],"schema_version":"1.9.0"}