PT-2020-6415 · Unknown · Jerryscript
Owl337
·
Published
2020-06-01
·
Updated
2021-06-16
·
CVE-2020-23314
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
JerryScript version 2.2.0
Description
The issue is related to the
parser parse try statement end function in the js-parser-statm.c component of the JerryScript JavaScript engine for the Internet of Things. It involves an insufficient use of the assert() function, which can be exploited by a remote attacker to cause a denial of service.Recommendations
For JerryScript version 2.2.0, consider applying a patch or fix that properly implements the
assert() function in the parser parse try statement end function to prevent potential denial of service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jerryscript