file-type vulnerable to Infinite Loop via malformed MKV file
High severity
GitHub Reviewed
Published
Jul 22, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Package
Affected versions
>= 17.0.0, < 17.1.3
>= 13.0.0, < 16.5.4
Patched versions
17.1.3
16.5.4
Description
Published by the National Vulnerability Database
Jul 21, 2022
Published to the GitHub Advisory Database
Jul 22, 2022
Reviewed
Jul 22, 2022
Last updated
Jan 28, 2023
An issue was discovered in the file-type package from 13.0.0 until 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unresponsive and could be used to cause a DoS attack when used on a web server.
References