PT-2021-19559 · Cesanta · Mongooseos Mjs

Ex0Dus-0X

·

Published

2021-04-29

·

Updated

2024-08-03

·

CVE-2021-31875

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Cesanta MongooseOS mJS version 1.26
Description: A maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs json parse(), potentially leading to redirection of control flow. The original reporter disputes the significance of this finding, stating that there is little opportunity to exploit this reliably for an information leak, and thus, no real security impact.
Recommendations: For version 1.26, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2021-31875

Affected Products

Mongooseos Mjs