Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qp8g-8mj4-549c

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

njs through 0.3.3, used in NGINX, has a heap-based buffer over-read in nxt_vsprintf in nxt/nxt_sprintf.c during error handling, as demonstrated by an njs_regexp_literal call that leads to an njs_parser_lexer_error call and then an njs_parser_scope_error call.

njs through 0.3.3, used in NGINX, has a heap-based buffer over-read in nxt_vsprintf in nxt/nxt_sprintf.c during error handling, as demonstrated by an njs_regexp_literal call that leads to an njs_parser_lexer_error call and then an njs_parser_scope_error call.

EPSS

Процентиль: 52%
0.00288
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 6.5
nvd
больше 6 лет назад

njs through 0.3.3, used in NGINX, has a heap-based buffer over-read in nxt_vsprintf in nxt/nxt_sprintf.c during error handling, as demonstrated by an njs_regexp_literal call that leads to an njs_parser_lexer_error call and then an njs_parser_scope_error call.

CVSS3: 6.5
fstec
больше 6 лет назад

Уязвимость интерпретатора njs сервера nginx, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 52%
0.00288
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-125