PT-2018-9489 · Samsung · Jerryscript
Marcin Dominiak
+1
·
Published
2018-08-20
·
Updated
2018-11-07
·
CVE-2018-1000636
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
JerryScript versions prior to the version containing commit 87897849f6879df10e8ad68a41bf8cf507edf710
Description
The issue is a NULL Pointer Dereference that can cause a crash due to a segmentation fault. This occurs when undefined behavior is triggered by passing NULL to
memcpy as the 2nd argument in the ecma-builtin-typedarray-prototype.c file, resulting in a null pointer dereference at jmem-heap.c. The attack is exploitable via specially crafted JavaScript code that the victim must execute.Recommendations
For JerryScript versions prior to the version containing commit 87897849f6879df10e8ad68a41bf8cf507edf710, update to a version that includes the fix for this issue.
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jerryscript