CVE-2022-36313
21.07.2022, 16:15
An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unresponsive and could be used to cause a DoS attack.
Vendor | Product | Version |
---|---|---|
file-type_project | file-type | 𝑥 < 16.5.4 |
file-type_project | file-type | 17.0.0 ≤ 𝑥 < 17.1.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References