Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Dominiakm

#25890de 53,634
9.8CVSS total
Vulnerabilidades · 1
PT-2019-11495
9.8
2019-07-25
Samsung · Jerryscript · CVE-2019-1010176
Name of the Vulnerable Software and Affected Versions: JerryScript versions prior to the version after commit 505dace719aebb3308a3af223cfaa985159efae0 Description: The issue is related to a buffer overflow, which can lead to denial of service and possibly arbitrary code execution. This occurs when executing crafted JavaScript code. The component involved is the `lit char to utf8 bytes` function, located in `jerry-core/lit/lit-char-helpers.c:377`. Recommendations: For versions prior to the fixed version, update to a version after commit 505dace719aebb3308a3af223cfaa985159efae0 to resolve the issue. As a temporary workaround, consider restricting the execution of crafted JavaScript code to minimize the risk of exploitation.