Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
IT Security NachrichtenMcDonald's Reportedly Using AI to 'Dynamically' Price Its Burgers(29.09.2026 um 22:00 Uhr)
•
IT Security DownloadsGitHub Release: NousResearch/hermes-agent vrc.29-v0.21.5 (29.09.2026)(29.09.2026 um 21:52 Uhr)
•
IT Security DownloadsGitHub Release: NousResearch/hermes-agent vrc.30-v0.21.5 (29.09.2026)(29.09.2026 um 21:55 Uhr)
••••••••
IT Security NachrichtenMcDonald's Reportedly Using AI to 'Dynamically' Price Its Burgers(29.09.2026 um 22:00 Uhr)
•
IT Security DownloadsGitHub Release: NousResearch/hermes-agent vrc.29-v0.21.5 (29.09.2026)(29.09.2026 um 21:52 Uhr)
•
IT Security DownloadsGitHub Release: NousResearch/hermes-agent vrc.30-v0.21.5 (29.09.2026)(29.09.2026 um 21:55 Uhr)
••••••••
Intelligence View
⚡ tsecurity.de Intelligence

Node.js third-party modules: Pixel flood attack cause the javascript heap out of memory

I would like to report Pixel flood attack in jimp It allows flooding the memory and causing DoS by uploading a crafted image (5kb image), and the Jimp module will tries to allocate 4128062500 pixels into memory. Module module name: jimp…

0
↗ Quelle (vulners.com)
Reagiere als Erste:r — dein Feedback zählt!

image
I would like to report Pixel flood attack in jimp It allows flooding the memory and causing DoS by uploading a crafted image (5kb image), and the Jimp module will tries to allocate 4128062500 pixels into memory. Module module name: jimp version: <=0.10.1 npm page: https://www.npmjs.com/package/jimp Module Description An image processing library for Node written entirely in JavaScript, with zero native dependencies. Module Stats 1,053,700 Weekly Downloads Vulnerability Vulnerability Description The jimp module will load the pixel from the image file to the memory, and processing the image in order to get a new image file such as resize, rotate, blur, etc. The jimp using EXIF data for picture orientation, which was causing run out of memory in the system. The attacker could manipulate the exif data in the image file such as change the image pixel to 64250x64250pixels. If the jimp module loaded the crafted image, it tries to allocate 4128062500 pixels into memory. Steps To Reproduce: First, install the jimp module : npm install --save jimp Second, download a crafted image from the attachment (lottapixel.jpg). Finally, create index.js file as the PoC code below and execute. ``` var Jimp = require('jimp'); Jimp.read('lottapixel.jpg', (err, lenna) => { if (err) throw err; lenna .resize(256, 256) // resize .quality(60) // set JPEG quality .greyscale() // set greyscale .write('image-small-bw.jpg'); // save }); ``` The output will display the error...
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Node.js third-party modules: Pixel flood attack cause the javascript heap out of memory

Thematisch verwandte Begriffe: Nodejs, thirdparty, modules, Pixel · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-102827 | simple-git, an interface for running git commands in any node.js applic…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag