Bug 1578234 - nodejs-mysql: Uninitialized memory disclosure in when a number is provided as a password
Summary: nodejs-mysql: Uninitialized memory disclosure in when a number is provided as...
Keywords:
Status: CLOSED UPSTREAM
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1578235 1578236 1578610
Blocks: 1578237
TreeView+ depends on / blocked
 
Reported: 2018-05-15 05:31 UTC by Sam Fowler
Modified: 2021-02-17 00:19 UTC (History)
8 users (show)

Fixed In Version: nodejs-mysql 2.14.0
Clone Of:
Environment:
Last Closed: 2020-05-20 21:17:25 UTC
Embargoed:


Attachments (Terms of Use)

Description Sam Fowler 2018-05-15 05:31:12 UTC
Versions of mysql before 2.14.0 are vulnerable to remove memory exposure.

Affected versions of mysql package allocate and send an uninitialized memory over the network when a number is provided as a password.

Only mysql running on Node.js versions below 6.0.0 is affected due to a throw added in newer node.js versions.


External Reference:

https://nodesecurity.io/advisories/602


Upstream Commit:

https://github.com/mysqljs/mysql/commit/310c6a7d1b2e14b63b572dbfbfa10128f20c6d52

Comment 1 Sam Fowler 2018-05-15 05:31:34 UTC
Created nodejs-mysql tracking bugs for this issue:

Affects: epel-all [bug 1578236]
Affects: fedora-all [bug 1578235]

Comment 3 Product Security DevOps Team 2020-05-20 21:17:25 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.

Comment 4 Product Security DevOps Team 2020-05-21 03:15:19 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.


Note You need to log in before you can comment on or make changes to this bug.