PT-2021-10809 · Jsish · Jsish

Bird8693

·

Published

2021-07-13

·

Updated

2021-07-15

·

CVE-2020-22907

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions jsish versions prior to 3.0.18
Description The issue is related to a stack overflow vulnerability in the jsi evalcode sub function. This vulnerability allows remote attackers to cause a Denial of Service by providing a crafted value to the execute parameter.
Recommendations For versions prior to 3.0.18, update to version 3.0.18 or later to resolve the issue.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-22907

Affected Products

Jsish