Description
This affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service. **Note:** This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2758 Vulnerability (CVE-2019-2758)
Sqlite NULL Pointer Dereference Vulnerability (CVE-2017-15286)
Moodle Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-3809)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2011-4133)
PostgreSQL Resource Management Errors Vulnerability (CVE-2012-2655)