PT-2019-11491 · Jsish · Jsish

Publicado

2019-07-23

·

Atualizado

2019-07-23

·

CVE-2019-1010171

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Jsish version 2.4.83
Description: The issue is related to a null pointer dereference, which can cause a denial of service. It affects the jsi DumpFunctions function, located in jsiEval.c at line 567. The attack vector involves executing crafted JavaScript code.
Recommendations: For Jsish version 2.4.83, update to version 2.4.84 to resolve the issue. As a temporary workaround, consider avoiding the execution of crafted JavaScript code or restricting access to the jsi DumpFunctions function until the update is applied.

Exploit

Correção

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-1010171

Produtos afetados

Jsish