CVE Vulnerabilities

CVE-2022-36313

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jul 21, 2022 | Modified: Oct 27, 2022
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu

An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unresponsive and could be used to cause a DoS attack.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
File-type File-type_project * 16.5.4 (excluding)
File-type File-type_project 17.0.0 (including) 17.1.3 (excluding)
Red Hat Data Grid 8.4.1 RedHat file-type *

References