PT-2019-12520 · Nginx · Njs

Xeioexop

·

Published

2019-05-09

·

Updated

2022-03-24

·

CVE-2019-11837

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions njs versions prior to 0.3.2
Description The issue is related to a segmentation fault in String.prototype.toBytes for negative arguments. It is connected to the functions nxt utf8 next in nxt/nxt utf8.h and njs string offset in njs/njs string.c. This problem is found in njs, which is used in NGINX.
Recommendations For versions prior to 0.3.2, update to version 0.3.2 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11837

Affected Products

Njs