PT-2023-12223 · Artifex · Artifex Mujs

Shaohuali

·

Published

2023-04-17

·

Updated

2023-04-27

·

CVE-2021-33797

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Artifex MuJS versions 1.0.1 through 1.1.1
Description The issue is related to a buffer overflow in the jsdtoa.c file of Artifex MuJS. This occurs due to an integer overflow when the js strtod() function reads in a floating point exponent, leading to a buffer overflow in the pointer *d.
Recommendations For Artifex MuJS versions 1.0.1 through 1.1.1, consider updating to a version that fixes the buffer overflow issue in jsdtoa.c. As a temporary workaround, consider restricting the input to the js strtod() function to prevent integer overflows.

Exploit

Fix

Integer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33797

Affected Products

Artifex Mujs