Lucene search

K
ubuntucveUbuntu.comUB:CVE-2017-20162
HistoryJan 05, 2023 - 12:00 a.m.

CVE-2017-20162

2023-01-0500:00:00
ubuntu.com
ubuntu.com
13
vulnerability
vercel ms
parse function
remote attack
upgrade
regular expression complexity
patch
cve-2017-20162

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:N/A:P

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS

0.002

Percentile

54.5%

A vulnerability, which was classified as problematic, has been found in
vercel ms up to 1.x. This issue affects the function parse of the file
index.js. The manipulation of the argument str leads to inefficient regular
expression complexity. The attack may be initiated remotely. The exploit
has been disclosed to the public and may be used. Upgrading to version
2.0.0 is able to address this issue. The patch is named
caae2988ba2a37765d055c4eee63d383320ee662. It is recommended to upgrade the
affected component. The associated identifier of this vulnerability is
VDB-217451.

Notes

Author Note
alexmurray The Debian chromium source package is called chromium-browser in Ubuntu
mdeslaur starting with Ubuntu 19.10, the chromium-browser package is just a script that installs the Chromium snap
ccdm94 chromium-browser, npm and qt6-webengine seem to contain embedded copies of vercel/ms, which is a node package (https://www.npmjs.com/ package/ms).

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:N/A:P

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS

0.002

Percentile

54.5%

Related for UB:CVE-2017-20162