Junglewise Threat Intelligence

CVE-2016-10518: websockets ws remote memory disclosure via uninitialized buffers

CVE-2016-10518 · Severity: info · CVSS 7.5 · Published 2019-02-18

Technologies: ws (npm). Vendors: npm.

Executive brief

The 'ws' library, a popular WebSocket implementation for Node.js, contains a vulnerability that can lead to the accidental disclosure of sensitive server or client memory. If an application allows user-provided numbers to be passed into certain communication functions, the library may transmit uninitialized memory buffers instead of the intended data. This could allow an attacker to view fragments of previously processed data, such as passwords, session tokens, or other private information stored in the system's memory.

Technical details

A vulnerability exists in the 'ws' module before version 1.0.1 due to improper handling of numeric arguments in the ping(), pong(), and send() methods. In Node.js, passing a number to the Buffer constructor allocates a new buffer of that size without zero-filling it, leaving existing data from previous memory allocations intact. When 'ws' receives a numeric argument for these methods, it creates a buffer of that size and transmits its uninitialized contents over the network. This allows a remote attacker to trigger memory disclosure if the application logic passes untrusted input directly into these functions. The fix, implemented in version 1.0.1, ensures that numeric inputs are properly validated or converted to strings before buffer allocation.

Affected products

  • websockets ws < 1.0.1

Timeline

  • 2016-01-04: patched: Version 1.0.1 released to address the buffer vulnerability.
  • 2018-05-31: advisory: NVD published CVE-2016-10518.
  • 2019-02-18: disclosed: GitHub Advisory GHSA-2mhh-w6q8-5hxw published.

References

Related threats