An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unresponsive and could be used to cause a DoS attack.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Name | Vendor | Start Version | End Version |
---|---|---|---|
File-type | File-type_project | * | 16.5.4 (excluding) |
File-type | File-type_project | 17.0.0 (including) | 17.1.3 (excluding) |
Red Hat Data Grid 8.4.1 | RedHat | file-type | * |