Junglewise Threat Intelligence

CVE-2022-36313: file-type infinite loop via malformed MKV file

CVE-2022-36313 · Severity: low · CVSS 3.1 · Published 2022-07-22

Technologies: Sindre Sorhus File-Type.

Executive brief

file-type is a Node.js library that detects file types by inspecting file contents. A malformed MKV (Matroska video) file can cause the detector to enter an infinite loop, freezing the application. This can be exploited for denial-of-service attacks, especially when used in web services to render applications unresponsive.

Technical details

The file-type library contains an infinite loop vulnerability (CWE-835) in its MKV file format parser, affecting versions 13.0.0 through 16.5.3 and 17.0.0 through 17.1.2. A specially crafted malformed MKV file can trigger the infinite loop when processed by the file type detector, causing the application to hang indefinitely. The vulnerability is remotely exploitable with no authentication or user interaction required, as the library processes untrusted file input. An attacker can exploit this to achieve denial of service by uploading a malicious MKV file to a web application using this library. Patches are available in versions 16.5.4 and 17.1.3.

Affected products

  • Sindre Sorhus file-type 13.0.0 to 16.5.3, 17.0.0 to 17.1.2

Timeline

  • 2022-07-22: disclosed
  • 2022-07-22: patched: Fixes available in versions 16.5.4 and 17.1.3
  • 2022-07-21: other: CVE-2022-36313 published on NVD

References