nodeca / pako

high speed zlib port to javascript, works in browser & node.js

Home Page:http://nodeca.github.io/pako/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Pako and CVE-2018-25032 vulnerability

alex3683 opened this issue · comments

commented

I'm using pako in version 1.0.11 via jszip and wanted to know, whether this is affected by CVE-2018-25032 or not. I'm unsure whether by design JavaScript is not vulnerable to such an attack but wanted to make sure.

JS does not allows out of bounds writes.

commented

Ok, thanks for clarification.