CVE-2022-36313: Medium severity IBM Cloud Pak for Security vulnerability
A flaw was found in the file-type npm package. A malformed MKV file could lead the file type detector to a denial of Service. This issue allows an attacker to input a malicious file and make the server unresponsive.
Other sources
An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unresponsive and could be used to cause a DoS attack.
Node.js file-type module is vulnerable to a denial of service, caused by an infinite loop. By persuading a victim to open a specially-crafted MKV file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-36313?
CVE-2022-36313 is a vulnerability found in the file-type npm package that could be exploited to cause a denial-of-service (DoS) attack.
What is the severity of CVE-2022-36313?
CVE-2022-36313 has a severity rating of medium (5.5).
How does CVE-2022-36313 affect the file-type package?
CVE-2022-36313 affects the file-type package versions before 16.5.4 and 17.x before 17.1.3 for Node.js.
How can a malformed MKV file exploit CVE-2022-36313?
A malformed MKV file can cause the file type detector in the file-type package to enter an infinite loop, making the application unresponsive and triggering a DoS attack.
How can I fix CVE-2022-36313?
To fix CVE-2022-36313, update the file-type package to version 16.5.4 or 17.1.3, or upgrade to version 18.0.0.