PT-2021-19559 · Cesanta · Mongooseos Mjs
Ex0Dus-0X
·
Published
2021-04-29
·
Updated
2024-08-03
·
CVE-2021-31875
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Cesanta MongooseOS mJS version 1.26
Description:
A maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in
mjs json parse(), potentially leading to redirection of control flow. The original reporter disputes the significance of this finding, stating that there is little opportunity to exploit this reliably for an information leak, and thus, no real security impact.Recommendations:
For version 1.26, at the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mongooseos Mjs