Candidate: CVE-2017-18214 PublicDate: 2018-03-04 21:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18214 https://github.com/moment/moment/commit/69ed9d44957fa6ab12b73d2ae29d286a857b80eb https://github.com/moment/moment/pull/4326 https://github.com/moment/moment/issues/4163 https://nodesecurity.io/advisories/532 Description: The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055. Ubuntu-Description: It was discovered that moment mishandled certain regular expressions. An attacker could use this vulnerability to cause a denial of service. Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_node-moment: upstream_node-moment: released (2.19.3+ds-1) precise/esm_node-moment: DNE trusty_node-moment: DNE trusty/esm_node-moment: DNE xenial_node-moment: ignored (end of standard support, was needed) artful_node-moment: ignored (reached end-of-life) bionic_node-moment: not-affected (2.20.1+ds-1) cosmic_node-moment: not-affected (2.20.1+ds-1) disco_node-moment: not-affected (2.20.1+ds-1) eoan_node-moment: not-affected (2.20.1+ds-1) focal_node-moment: not-affected (2.20.1+ds-1) groovy_node-moment: not-affected (2.20.1+ds-1) hirsute_node-moment: not-affected (2.20.1+ds-1) impish_node-moment: not-affected (2.20.1+ds-1) jammy_node-moment: not-affected (2.20.1+ds-1) devel_node-moment: not-affected (2.20.1+ds-1)