Executive brief
node-lmdb is a Node.js library used to interact with the LMDB high-performance database. A vulnerability in how the library handles certain data types can allow an attacker to crash the application, leading to a denial of service. This could disrupt business operations by making database-dependent services unavailable.
Technical details
The node-lmdb package before version 0.9.7 is vulnerable to a Denial of Service (DoS) due to an unhandled case during type checking in the `TxnWrap::putString` method. Specifically, when the library expects a string but receives a value with a non-invokable or invalid `ToString` representation, it fails to validate the input type before processing. An attacker can exploit this by providing a non-string value to the affected method, causing the Node.js process to crash. The fix, introduced in version 0.9.7, adds an explicit check using `info[2]->IsString()` to ensure the input is a valid string before proceeding.
Affected products
- Venemo node-lmdb < 0.9.7
Timeline
- 2022-03-16: advisory: NVD publication date
- 2022-03-17: disclosed: GitHub Advisory published
- 2022-03-19: patched: GitHub reviewed the advisory and confirmed the fix in 0.9.7