3 ms·
Based on your comment, should we expect this vulnerability in comparable packages from other languages/communities? Or is this an NPM/JS maturity issue, i.e., “
by jtdev 6y ago
Based on your comment, should we expect this vulnerability in comparable packages from other languages/communities? Or is this an NPM/JS maturity issue, i.e., “it’s not my fault, fix the spec.”?
- FDSGSG 6y agoThis is a super common bug.
- fanf2 6y agoIt’s obscure enough that I would expect this bug to turn up elsewhere, even though it’s an example of a fundamental security risk of parsers that don’t accept the same syntax (http://langsec.org/ http://langsec.org/), and IPv4 addresses are a specific instance of this risk that has been written about for years. (Tho usually the weirdness of inet_aton() is treated as quirky rather than dangerous.) I like the twist in the vulnerability report, using differences between IPv4 parsers to get past protections against things like SSRF, which I don’t think is explicitly mentioned in the IETF draft and RFC that I linked to.
- fanf2 6y agoAnd as predicted, the issue is turning up in other places, for instance https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/ https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-... (comments https://news.ycombinator.com/item?id=26628827 https://news.ycombinator.com/item?id=26628827)