PT-2023-12423 · Unknown · Serenityos
William Bowling
·
Published
2023-03-01
·
Updated
2024-05-17
·
CVE-2021-4327
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SerenityOS (affected versions not specified)
Description
A critical issue has been found in SerenityOS, affecting the function
initialize typed array from array buffer in the library Userland/Libraries/LibJS/Runtime/TypedArray.cpp. This issue leads to integer overflow. The exploit has been disclosed to the public and may be used.Recommendations
To fix this issue, it is recommended to apply a patch, specifically the one identified as f6c6047e49f1517778f5565681fb64750b14bf60. As a temporary workaround, consider disabling the
initialize typed array from array buffer function until the patch is applied.Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Serenityos