Out-of-bounds Read in npmconf
Moderate severity
GitHub Reviewed
Published
Jun 12, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jun 12, 2019
Published to the GitHub Advisory Database
Jun 12, 2019
Last updated
Jan 9, 2023
Versions of
npmconf
before 2.1.3 allocate and write to disk uninitialized memory contents when a typed number is passed as input on Node.js 4.x.Recommendation
Update to version 2.1.3 or later. Consider switching to another config storage mechanism, as npmconf is deprecated and should not be used.
References