Publish Advisories

GHSA-7vhm-fmph-7wxw
GHSA-g533-xq5w-jmf3
This commit is contained in:
advisory-database[bot]
2024-07-10 20:44:50 +00:00
parent 26eb47b769
commit 92ab161f3d
2 changed files with 64 additions and 10 deletions
@@ -1,20 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7vhm-fmph-7wxw",
"modified": "2024-07-10T06:33:52Z",
"modified": "2024-07-10T20:43:22Z",
"published": "2024-07-10T06:33:51Z",
"aliases": [
"CVE-2024-21522"
],
"summary": "audify vulnerable to Improper Validation of Array Index",
"details": "All versions of the package audify are vulnerable to Improper Validation of Array Index when frameSize is provided to the new OpusDecoder().decode or new OpusDecoder().decodeFloat functions it is not checked for negative values. This can lead to a process crash.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
}
],
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "audify"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.9.0"
}
]
}
]
}
],
"references": [
{
@@ -25,9 +48,13 @@
"type": "WEB",
"url": "https://gist.github.com/dellalibera/6bb866ae5d1cc2adaabe27bbd6d2d21e"
},
{
"type": "PACKAGE",
"url": "https://github.com/almoghamdani/audify"
},
{
"type": "WEB",
"url": "https://github.com/almoghamdani/audify/blob/94b2fe79dc528fda2c7d59c7a0fd0e9de07dc3dc/src/opus_decoder.cpp%23L53"
"url": "https://github.com/almoghamdani/audify/blob/94b2fe79dc528fda2c7d59c7a0fd0e9de07dc3dc/src/opus_decoder.cpp#L53"
},
{
"type": "WEB",
@@ -43,8 +70,8 @@
"CWE-129"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-07-10T20:43:22Z",
"nvd_published_at": "2024-07-10T05:15:10Z"
}
}
@@ -1,20 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g533-xq5w-jmf3",
"modified": "2024-07-10T06:33:52Z",
"modified": "2024-07-10T20:43:35Z",
"published": "2024-07-10T06:33:52Z",
"aliases": [
"CVE-2024-21524"
],
"summary": "node-stringbuilder vulnerable to Out-of-bounds Read",
"details": "All versions of the package node-stringbuilder are vulnerable to Out-of-bounds Read due to incorrect memory length calculation, by calling ToBuffer, ToString, or CharAt on a StringBuilder object with a non-empty string value input. It's possible to return previously allocated memory, for example, by providing negative indexes, leading to an Information Disclosure.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"
}
],
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "node-stringbuilder"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.2.7"
}
]
}
]
}
],
"references": [
{
@@ -25,9 +48,13 @@
"type": "WEB",
"url": "https://gist.github.com/dellalibera/0bb022811224f81d998fa61c3175ee67"
},
{
"type": "PACKAGE",
"url": "https://github.com/magiclen/node-stringbuilder"
},
{
"type": "WEB",
"url": "https://github.com/magiclen/node-stringbuilder/blob/5c2797d3d6bf8cb6d10fe1e077609cef9a5a7de0/src/node-stringbuilder.c%23L1281"
"url": "https://github.com/magiclen/node-stringbuilder/blob/5c2797d3d6bf8cb6d10fe1e077609cef9a5a7de0/src/node-stringbuilder.c#L1281"
},
{
"type": "WEB",
@@ -39,8 +66,8 @@
"CWE-125"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-07-10T20:43:35Z",
"nvd_published_at": "2024-07-10T05:15:11Z"
}
}