Junglewise Threat Intelligence

CVE-2018-3745: atob out-of-bounds read on numeric input

CVE-2018-3745 · Severity: low · CVSS 3.1 · Published 2018-10-09

Vendors: npm.

Executive brief

The atob library, a Base64 decoding utility used in Node.js applications, contains an out-of-bounds memory read vulnerability when processing numeric input on older Node.js versions. An attacker could exploit this to read sensitive memory contents, potentially exposing secrets or causing application crashes.

Technical details

The vulnerability exists in atob versions before 2.1.0 and is triggered when a number is passed as input on Node.js 4.x and below, causing uninitialized buffers to be created. This is a CWE-125 out-of-bounds read issue that allows an attacker with network access to send crafted input and read beyond allocated memory boundaries. The attack requires no authentication or user interaction. An attacker can leverage this to leak sensitive data from process memory, including credentials, keys, or other confidential information. The fix is available in version 2.1.0 and later.

Affected products

  • npm atob <2.1.0

Timeline

  • 2018-05-29: disclosed
  • 2018-10-09: patched

References