CVE Database
/

CVE-2020-8252

Back to search

CVE-2020-8252

Published: Sep 18, 2020

Modified: Apr 30, 2025

PUBLISHED

Description

The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes.

VendorProductVersions

NodeJS

Node

affected
4.0 - < 4.*
affected
5.0 - < 5.*
affected
6.0 - < 6.*
affected
7.0 - < 7.*
affected
8.0 - < 8.*

+6 more versions

Weaknesses (CWE)

References

GLSA-202009-15
vendor-advisory
x_refsource_GENTOO
USN-4548-1
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2020:1616
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:1660
vendor-advisory
x_refsource_SUSE
FEDORA-2020-43d5a372fc
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now