Unrated severityNVD Advisory· Published Aug 14, 2020· Updated Aug 4, 2024
CVE-2020-15694
CVE-2020-15694
Description
In Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example, httpClient.get().contentLength() does not raise any error if a malicious server provides a negative Content-Length.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- Nim/Nimdescription
- osv-coords5 versionspkg:rpm/opensuse/nim&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/nim&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/nim&distro=openSUSE%20Tumbleweedpkg:rpm/suse/nim&distro=SUSE%20Package%20Hub%2015%20SP3pkg:rpm/suse/nim&distro=SUSE%20Package%20Hub%2015%20SP4
< 1.6.6-bp153.2.3.1+ 4 more
- (no CPE)range: < 1.6.6-bp153.2.3.1
- (no CPE)range: < 1.6.6-bp154.2.3.1
- (no CPE)range: < 1.6.6-3.1
- (no CPE)range: < 1.6.6-bp153.2.3.1
- (no CPE)range: < 1.6.6-bp154.2.3.1
Patches
Vulnerability mechanics
References
4- www.openwall.com/lists/oss-security/2021/02/04/2mitremailing-listx_refsource_MLIST
- consensys.net/diligence/vulnerabilities/nim-httpclient-header-crlf-injection/mitrex_refsource_MISC
- github.com/nim-lang/Nim/blob/dc5a40f3f39c6ea672e6dc6aca7f8118a69dda99/lib/pure/httpclient.nimmitrex_refsource_MISC
- nim-lang.org/blog/2020/07/30/versions-126-and-108-released.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.