CVE-2022-24434

NameCVE-2022-24434
DescriptionThis affects all versions of package dicer. A malicious attacker can send a modified form to server, and crash the nodejs service. An attacker could sent the payload again and again so that the service continuously crashes.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-superagent (PTS)buster0.20.0+dfsg-2fixed
bullseye6.1.0-4fixed
bookworm8.0.5-1fixed
sid, trixie9.0.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-superagentsource(unstable)(not affected)

Notes

- node-superagent <not-affected> (Vulnerable code only exists in Debian autopkgtest support)
https://github.com/mscdex/busboy/issues/250
https://github.com/mscdex/dicer/pull/22/commits/b7fca2e93e8e9d4439d8acc5c02f5e54a0112dac
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2838865
https://snyk.io/vuln/SNYK-JS-DICER-2311764

Search for package or bug name: Reporting problems