node-weakauras-parser@2.0.1 vulnerabilities

Native module for Node.js that does deserialization/serialization of WeakAuras' strings

Direct Vulnerabilities

Known vulnerabilities in the node-weakauras-parser package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Buffer Overflow

node-weakauras-parser is a native module for Node.js that does deserialization/serialization of WeakAuras' strings.

Affected versions of this package are vulnerable to Buffer Overflow. The encode_weakaura function fails to properly validate the input size. A buffer of 13835058055282163711 bytes causes an overflow on 64-bit systems.

How to fix Buffer Overflow?

Upgrade node-weakauras-parser to version 1.0.5, 2.0.2, 3.0.1 or higher.

>=1.0.4 <1.0.5 >=2.0.0 <2.0.2 >=3.0.0 <3.0.1