Описание
An issue was discovered in ecma-helpers.c in jerryscript version 2.3.0, allows local attackers to cause a denial of service (DoS) (Null Pointer Dereference).
Ссылки
- https://github.com/Aurorainfinity/Poc/tree/master/jerryscript/NULL-dereference-ecma_get_lex_env_typeExploitThird Party Advisory
- Vendor Advisory
- https://github.com/Aurorainfinity/Poc/tree/master/jerryscript/NULL-dereference-ecma_get_lex_env_typeExploitThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:jerryscript:jerryscript:2.3.0:*:*:*:*:*:*:*
EPSS
Процентиль: 9%
0.00031
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-476
Связанные уязвимости
CVSS3: 5.5
ubuntu
больше 2 лет назад
An issue was discovered in ecma-helpers.c in jerryscript version 2.3.0, allows local attackers to cause a denial of service (DoS) (Null Pointer Dereference).
CVSS3: 5.5
debian
больше 2 лет назад
An issue was discovered in ecma-helpers.c in jerryscript version 2.3.0 ...
CVSS3: 5.5
github
больше 2 лет назад
An issue was discovered in ecma-helpers.c in jerryscript version 2.3.0, allows local attackers to cause a denial of service (DoS) (Null Pointer Dereference).
EPSS
Процентиль: 9%
0.00031
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-476