A security issue was found in bittorrent-dht before 5.1.3 that allows someone to send a specific series of messages to a listening peer and get it to reveal internal memory.
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://nodesecurity.io/advisories/68 | third party advisory |
https://github.com/feross/bittorrent-dht/issues/87 | third party advisory |