PT-2026-25330 · Debian+3 · Lexbor
CVSS v4.0
8.2
Alta
| Vetor | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Lexbor versions prior to 2.7.0
Description
Lexbor is a web browser engine library. Before version 2.7.0, the ISO‑2022‑JP encoder in Lexbor does not reset the temporary size variable between iterations. The statement
ctx->buffer used -= size with an outdated size of 3 causes an integer underflow that wraps to SIZE MAX. Subsequently, memcpy is called with a negative length, resulting in an out-of-bounds read from the stack and an out-of-bounds write to the heap. The source data is partially controllable through the contents of the DOM tree.Recommendations
Versions prior to 2.7.0 should be updated to version 2.7.0 or later.
Exploit
Correção
Integer Underflow
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Lexbor