The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes.
https://usn.ubuntu.com/4548-1/
https://security.netapp.com/advisory/ntap-20201009-0004/
https://security.gentoo.org/glsa/202009-15
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OOYAMJVLLCLXDTHW3V5UXNULZBBK4O6/
https://hackerone.com/reports/965914
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00023.html
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00011.html
https://nodejs.org/en/blog/vulnerability/september-2020-security-releases/
Source: Mitre, NVD
Published: 2020-09-18
Updated: 2024-11-21
Base Score: 4.6
Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P
Severity: Medium
Base Score: 7.8
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.001