CVE-2019-11411
CVE-2019-11411
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 3.3%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
21 Apr 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An issue was discovered in Artifex MuJS 1.0.5. The Number#toFixed() and numtostr implementations in jsnumber.c have a stack-based buffer overflow.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://bugs.ghostscript.com/show_bug.cgi?id=700938https://github.com/ccxvii/mujs/commit/da632ca08f240590d2dec786722ed08486ce1be6https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3RQXMWEOWCGLOLFBQSXBM3MBN33T4I5H/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/67PMOZV4DLVL2KGU2SV724QL7Y4PKWKU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MFCRO74ORRIVWNVAX2MAMRY3THCTWLQI/https://security.gentoo.org/glsa/202007-52http://www.ghostscript.com/cgi-bin/findgit.cgi?da632ca08f240590d2dec786722ed08486ce1be6http://www.securityfocus.com/bid/108093