Skip to main content

Improper Check or Handling of Exceptional Conditions

CVE-2024-21525

Severity High
Score 8.3/10

Summary

All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the length of the source data not being checked. Creating a new "twain.TwainSDK" with a "productName" or "productFamily", "manufacturer", "version.info" property of "length >= 34" chars leads to a buffer overflow vulnerability.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • REQUIRED
  • NONE
  • HIGH
  • LOW

CWE-703 - Improper Check or Handling of Exceptional Conditions

The software does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the software.

Advisory Timeline

  • Published