Lucene search

K
nodejsSteve KempNODEJS:153
HistoryOct 27, 2016 - 4:23 p.m.

Command Injection

2016-10-2716:23:56
Steve Kemp
www.npmjs.com
36

0.003 Low

EPSS

Percentile

65.2%

Overview

Affected versions of dns-sync are vulnerable to arbitrary command execution via maliciously formed hostnames.

Proof of Concept

    var dnsSync = require('dns-sync');
    console.log(dnsSync.resolve('$(id > /tmp/foo)'));

Recommendation

Update to version 0.1.1 or later.

References

CPENameOperatorVersion
dns-synclt0.1.1

0.003 Low

EPSS

Percentile

65.2%