CVE-2024-27088

NameCVE-2024-27088
Descriptiones5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the script to stall. The vulnerability is patched in v0.10.63.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1064933

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-es5-ext (PTS)buster0.10.30-1vulnerable
bullseye0.10.53+~1.1.0-1vulnerable
sid, trixie, bookworm0.10.62+dfsg1+~1.1.0-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-es5-extsource(unstable)(unfixed)1064933

Notes

[bookworm] - node-es5-ext <no-dsa> (Minor issue)
[bullseye] - node-es5-ext <no-dsa> (Minor issue)
[buster] - node-es5-ext <no-dsa> (Minor issue)
https://github.com/medikoo/es5-ext/security/advisories/GHSA-4gmj-3p3h-gm8h
https://github.com/medikoo/es5-ext/issues/201
https://github.com/medikoo/es5-ext/commit/3551cdd7b2db08b1632841f819d008757d28e8e2 (v1.10.63)
https://github.com/medikoo/es5-ext/commit/a52e95736690ad1d465ebcd9791d54570e294602 (v1.10.63)

Search for package or bug name: Reporting problems