PT-2022-10235 · Mjs · Mjs

Clingto

·

Published

2022-07-26

·

Updated

2022-07-28

·

CVE-2021-33439

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions mjs (affected versions not specified)
Description An issue was discovered in mjs, a Restricted JavaScript engine, specifically in ES6 (JavaScript version 6), where there is an integer overflow in the gc compact strings() function in mjs.c.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33439

Affected Products

Mjs