CVE-2015-5380

UnknownEPSS 3.00%

Last modified

CVE-2015-5380 is a vulnerability of currently unknown severity. The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.. EPSS estimates a 3.00% chance of exploitation in the next 30 days.

Description

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.

Metrics

EPSS Probability
3.00%

85.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
GoogleV8All versions
IojsIo.Js<= 1.8.2
IojsIo.Js2.0.0
IojsIo.Js2.0.1
IojsIo.Js2.0.2
IojsIo.Js2.1.0
IojsIo.Js2.2.0
IojsIo.Js2.2.1
IojsIo.Js2.3.0
IojsIo.Js2.3.1
IojsIo.Js2.3.2
NodejsNode.Js<= 0.12.5

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-5380?
The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.
How severe is CVE-2015-5380?
Severity scoring for CVE-2015-5380 is pending analysis. The EPSS model estimates a 3.00% probability of exploitation in the next 30 days.
How do I fix CVE-2015-5380?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-5380?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST