CVE-2016-4055 PUBLISHED

The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."

EPSS 2.71% · 85.8th percentile

Risk Scores

EPSS Score
2.71%
85.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSnode-moment0, 2.10.6+dfsg-1, 2.11.0+ds-1

Timeline

References

Open in Interactive Console →