PT-2020-6415 · Unknown · Jerryscript

Owl337

·

Published

2020-06-01

·

Updated

2021-06-16

·

CVE-2020-23314

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions JerryScript version 2.2.0
Description The issue is related to the parser parse try statement end function in the js-parser-statm.c component of the JerryScript JavaScript engine for the Internet of Things. It involves an insufficient use of the assert() function, which can be exploited by a remote attacker to cause a denial of service.
Recommendations For JerryScript version 2.2.0, consider applying a patch or fix that properly implements the assert() function in the parser parse try statement end function to prevent potential denial of service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04635
CVE-2020-23314

Affected Products

Jerryscript