Candidate: CVE-2016-10707 PublicDate: 2018-01-18 23:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10707 https://github.com/jquery/jquery/pull/3134 https://snyk.io/vuln/npm:jquery:20160529 Description: jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any attribute getter using a mixed-cased name for boolean attributes goes into an infinite recursion, exceeding the stack call limit. Ubuntu-Description: Notes: mdeslaur> only affected 3.0.0-rc.1 Bugs: https://github.com/jquery/jquery/issues/3133 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_jquery: other: https://github.com/jquery/jquery/commit/e06fda69f00082b44fd39ce8e851f72d29999011.patch upstream_jquery: released (3.1.1-1) precise/esm_jquery: not-affected (code not present) trusty_jquery: not-affected (code not present) trusty/esm_jquery: not-affected (code not present) xenial_jquery: not-affected (code not present) esm-infra/xenial_jquery: not-affected (code not present) artful_jquery: not-affected (3.1.1-2) devel_jquery: not-affected