[Bug 1195954] New: VUL-1: CVE-2021-45005: mujs: heap buffer overflow caused by conflicting JumpList of nested try/finally statements
http://bugzilla.opensuse.org/show_bug.cgi?id=1195954 Bug ID: 1195954 Summary: VUL-1: CVE-2021-45005: mujs: heap buffer overflow caused by conflicting JumpList of nested try/finally statements Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.4 Hardware: Other URL: https://smash.suse.de/issue/323776/ OS: Other Status: NEW Severity: Minor Priority: P5 - None Component: Security Assignee: ilya@ilya.pp.ua Reporter: carlos.lopez@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- CVE-2021-45005 Artifex MuJS v1.1.3 was discovered to contain a heap buffer overflow which is caused by conflicting JumpList of nested try/finally statements. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-45005 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45005 https://github.com/ccxvii/mujs/commit/df8559e7bdbc6065276e786217eeee70f28fce... https://bugs.ghostscript.com/show_bug.cgi?id=704749 -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1195954 http://bugzilla.opensuse.org/show_bug.cgi?id=1195954#c1 Carlos L�pez <carlos.lopez@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution|--- |INVALID --- Comment #1 from Carlos L�pez <carlos.lopez@suse.com> --- Already fixed in openSUSE:Factory. Closing. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1195954 Carlos L�pez <carlos.lopez@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Component|Security |Security Version|Leap 15.4 |Current Product|openSUSE Distribution |openSUSE Tumbleweed -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1195954 http://bugzilla.opensuse.org/show_bug.cgi?id=1195954#c2 --- Comment #2 from OBSbugzilla Bot <bwiedemann+obsbugzillabot@suse.com> --- This is an autogenerated message for OBS integration: This bug (1195954) was mentioned in https://build.opensuse.org/request/show/954741 Factory / mujs -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com