life_star@0.4.9 vulnerabilities

Another web server for Lively

  • latest version

    0.9.0

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    7 months ago

  • Direct Vulnerabilities

    Known vulnerabilities in the life_star package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Uninitialized Memory Exposure

    life_star is a web server for Lively.

    A possible memory disclosure vulnerability exists when a value of type number is provided to the buffer and results in concatenation of uninitialized memory to the buffer collection. This is a result of unobstructed use of the Buffer constructor, whose insecure default constructor increases the odds of memory leakage.

    You can read more about the insecure Buffer behavior on our blog.

    Similar vulnerabilities were discovered in bl, request, mongoose, ws and sequelize.

    Note This is vulnerable only for Node <=4

    <=0.8.4