Certain input strings when passed to new Date() or Date.parse() in ecstatic node module before 1.4.0 will cause v8 to raise an exception. This leads to a crash and denial of service in ecstatic when this input is passed into the server via the If-Modified-Since header.
The product does not properly control the allocation and maintenance of a limited resource.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://github.com/jfhbrook/node-ecstatic/pull/179 | issue tracking third party advisory |
https://bugs.chromium.org/p/v8/issues/detail?id=4640 | issue tracking third party advisory |
https://nodesecurity.io/advisories/64 | third party advisory |