Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-43453

Опубликовано: 07 апр. 2022
Источник: debian
EPSS Низкий

Описание

A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in parser_parse_for_statement_start in the js-parser-statm.c file. This issue is similar to CVE-2020-29657.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
iotjsremovedpackage
iotjsno-dsabusterpackage

Примечания

  • https://github.com/jerryscript-project/jerryscript/pull/4808

  • https://github.com/jerryscript-project/jerryscript/issues/4754

  • Fixed by: https://github.com/jerryscript-project/jerryscript/commit/efe63a5bbc5106164a08ee2eb415a7a701f5311f

EPSS

Процентиль: 59%
0.00385
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 4 года назад

A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in parser_parse_for_statement_start in the js-parser-statm.c file. This issue is similar to CVE-2020-29657.

CVSS3: 9.8
nvd
почти 4 года назад

A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in parser_parse_for_statement_start in the js-parser-statm.c file. This issue is similar to CVE-2020-29657.

CVSS3: 9.8
github
почти 4 года назад

A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in parser_parse_for_statement_start in the js-parser-statm.c file. This issue is similar to CVE-2020-29657.

EPSS

Процентиль: 59%
0.00385
Низкий