Junglewise Threat Intelligence

CVE-2018-3739: https-proxy-agent denial of service via unsanitized proxy options

CVE-2018-3739 · Severity: low · CVSS 3 · Published 2018-07-27

Technologies: https-proxy-agent (npm). Vendors: npm.

Executive brief

https-proxy-agent is a Node.js library used to establish HTTPS connections through a proxy server. Versions before 2.2.0 are vulnerable to denial of service attacks due to improper handling of the proxy.auth parameter, which can be exploited by an attacker to crash the application or consume excessive resources.

Technical details

The vulnerability exists in https-proxy-agent versions prior to 2.2.0 due to unsafe use of the deprecated Buffer constructor. The proxy.auth parameter is passed directly to new Buffer() without sanitization, triggering out-of-bounds read/write behavior (CWE-125, CWE-400). An attacker can supply crafted proxy authentication credentials to trigger a denial of service condition. This is a network-accessible vulnerability requiring no authentication or user interaction. The fix involves replacing new Buffer(proxy.auth) with the safe Buffer.from(proxy.auth) constructor, which properly validates input.

Affected products

  • TooTallNate https-proxy-agent < 2.2.0

Timeline

  • 2018-07-27: disclosed
  • 2018-07-27: patched: Version 2.2.0 released with Buffer.from() fix

References

Related threats