Sha256: 570e2b988f39c8e45c213dfcf723ae209ce6974af95faa8fe8718df1970e4bb7

Contents?: true

Size: 702 Bytes

Versions: 6

Compression:

Stored size: 702 Bytes

Contents

---
gem: uglifier
osvdb: 126747
url: https://github.com/mishoo/UglifyJS2/issues/751
title: uglifier incorrectly handles non-boolean comparisons during minification
date: 2015-07-21
description: |

  The upstream library for the Ruby uglifier gem, UglifyJS, is
  affected by a vulnerability that allows a specially crafted 
  Javascript file to have altered functionality after minification.

  This bug, found in UglifyJS versions 2.4.23 and earlier, was demonstrated
  to allow potentially malicious code to be hidden within secure code, 
  and activated by the minification process.

  For more information, consult: https://zyan.scripts.mit.edu/blog/backdooring-js/
patched_versions:
  - ">= 2.7.2"

Version data entries

6 entries across 6 versions & 2 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/uglifier/OSVDB-126747.yml
bundler-budit-0.6.2 data/ruby-advisory-db/gems/uglifier/OSVDB-126747.yml
bundler-budit-0.6.1 data/ruby-advisory-db/gems/uglifier/OSVDB-126747.yml
bundler-audit-0.6.1 data/ruby-advisory-db/gems/uglifier/OSVDB-126747.yml
bundler-audit-0.6.0 data/ruby-advisory-db/gems/uglifier/OSVDB-126747.yml
bundler-audit-0.5.0 data/ruby-advisory-db/gems/uglifier/OSVDB-126747.yml