Memory Corruption Vulnerability in Utf8DecoderBase::WriteUtf16Slow Function

Memory Corruption Vulnerability in Utf8DecoderBase::WriteUtf16Slow Function

CVE-2015-5380 · HIGH Severity


The Utf8DecoderBase::WriteUtf16Slow function in in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted byte sequence.

Learn more about our Web Application Penetration Testing UK.