
We found results for “”
WS-2016-0059
Good to know:


Date: January 19, 2016
Memory disclosure vulnerability in Bl before 0.9.5 and 1.0.0 allows concatination of uninitialized memory to the buffer collection when a value of type number is provided to the append() method.
Language: Java
Severity Score
Severity Score
Weakness Type (CWE)
Improper Initialization
CWE-665Top Fix

Upgrade Version
Upgrade to version spiral/toolkit - v0.9.0;spiral/toolkit - v0.8.20;spiral/toolkit - v0.8.18;bl - 0.9.5;NodeBin - no_fix;Npm.js - no_fix;NoGit - no_fix;adrexia/silverstripe-gumby-theme - 2;nodejs - 4.4.1;Ncapsulate.Node - no_fix;Ncapsulate.Node.Shadow - no_fix;node-sass-bundle - no_fix;Npm3 - no_fix;Ncapsulate.Bower - no_fix;Betclic.BuildTools.Node - no_fix;Npm - no_fix;neon-sys - 0.1.10;Bower - no_fix;nanny-sys - no_fix;org.webjars:npm:3.9.3
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | LOCAL |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |