HomeSecurityNpm: update JavaScript to avoid Binary Planting Bug

Npm: update JavaScript to avoid Binary Planting Bug

Npm

Npm urges users to update their JavaScript to the latest version (6.13.4) to avoid "Binary Planting" attacks.

In case you don't know, the company is the main maintainer of Node.js – a framework for JavaScript code that runs outside of the browser or server and allows you to manage npm packages via the CLI interface.

The service states that there is a flaw in the npm CLI client that could leave the system vulnerable to binary planting attacks. This flaw can be exploited by a malicious user only during the installation of an npm package via the npm CLI.

Two vulnerabilities were identified

In a post , German security researcher Daniel Ruf says he discovered two vulnerabilities in the npm CLI, which were designated as CVE-2019-16775, 16776, and 16777.

To include npm packages in code, developers list them in a file called package.json, and more specifically in a field called bin. All entries in this field point to a command in a local file name in the ./node_modules/.bin/ in the developer's project folder. As part of maintenance activities, npm may replace these files with new versions.

At this point, it is where a bug can allow an attack known as binary planting. Versions prior to 6.13.3 allow packages to access folders outside the intended folder by manipulating paths in the bin field.

In this way, a hacker can replace a file with a malicious one anywhere on the system or create a new file from scratch.

The second bug was found in bin-links (the npm package that manages the links from the bin field to the file in ./node_modules/.bin/, which is also present in the npm CLI).

A symlink (symbolic link) is used to manage these files. The flaw with Bin-links is that it allows packages to replace the symlink, even if they did not create it.

However, to carry out this attack, the hacker would have to convince a user to install a file by manipulating the bin field. While it is less likely, it is still possible.

There is a solution

The company has fixed these issues and is urging users to immediately update their npm CLI to version 6.13.4. It is also a good idea to check the bin field of your project's package.json files for any suspicious file paths.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS