Medium severity6.5NVD Advisory· Published Aug 30, 2020· Updated Jun 17, 2026
CVE-2020-8244
CVE-2020-8244
Description
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
blnpm | < 1.2.3 | 1.2.3 |
blnpm | >= 2.0.0, < 2.2.1 | 2.2.1 |
blnpm | >= 3.0.0, < 3.0.1 | 3.0.1 |
blnpm | >= 4.0.0, < 4.0.3 | 4.0.3 |
Affected products
4- bl/bldescription
- cpe:2.3:a:bufferlist_project:bufferlist:*:*:*:*:*:node.js:*:*Range: <1.2.3
Patches
Vulnerability mechanics
References
7- hackerone.com/reports/966347nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-pp7h-53gx-mx7rghsaADVISORY
- lists.debian.org/debian-lts-announce/2021/06/msg00028.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-8244ghsaADVISORY
- github.com/rvagg/bl/commit/8a8c13c880e2bef519133ea43e0e9b78b5d0c91eghsaWEB
- github.com/rvagg/bl/commit/d3e240e3b8ba4048d3c76ef5fb9dd1f8872d3190ghsaWEB
- github.com/rvagg/bl/commit/dacc4ac7d5fcd6201bcf26fbd886951be9537466ghsaWEB
News mentions
0No linked articles in our index yet.