Improper Check or Handling of Exceptional Conditions
CVE-2024-21525
Summary
All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the length of the source data not being checked. Creating a new "twain.TwainSDK" with a "productName" or "productFamily", "manufacturer", "version.info" property of "length >= 34" chars leads to a buffer overflow vulnerability.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- REQUIRED
- NONE
- HIGH
- LOW
CWE-703 - Improper Check or Handling of Exceptional Conditions
The software does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the software.
References
Advisory Timeline
- Published