GHSA-xm7f-x4wx-wmgv

Suggest an improvement
Source
https://github.com/advisories/GHSA-xm7f-x4wx-wmgv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-xm7f-x4wx-wmgv/GHSA-xm7f-x4wx-wmgv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xm7f-x4wx-wmgv
Published
2019-06-04T15:47:43Z
Modified
2020-08-31T18:31:36Z
Summary
Out-of-bounds Read in byte
Details

Versions of byte before 1.4.1 allocate uninitialized buffers and read data from them past the initialized length

Recommendation

Update to version 1.4.1 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-125"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-06-04T15:47:01Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / byte

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.4.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-xm7f-x4wx-wmgv/GHSA-xm7f-x4wx-wmgv.json"