Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1...
Critical severity
Unreviewed
Published
Apr 18, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Apr 17, 2023
Published to the GitHub Advisory Database
Apr 18, 2023
Last updated
Apr 4, 2024
Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when js_strtod() reads in floating point exponent, which leads to a buffer overflow in the pointer *d.
References