Out-of-Bounds read in stringstream
Moderate severity
GitHub Reviewed
Published
Jan 6, 2022
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Withdrawn
This advisory was withdrawn on Mar 19, 2021
Description
Reviewed
Mar 18, 2021
Withdrawn
Mar 19, 2021
Published to the GitHub Advisory Database
Jan 6, 2022
Last updated
Jan 9, 2023
Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).
WITHDRAWN
This is a duplicate of GHSA-mf6x-7mm4-x2g7
References