CRITICAL🇵🇱 Wersja polska

CVE-2021-31875

CVSS 9.8v3.1pub. 2021-04-29upd. 2024-11-21

In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_json_parse, which can potentially lead to redirection of control flow. NOTE: the original reporter disputes the significance of this finding because "there isn’t very much of an opportunity to exploit this reliably for an information leak, so there isn’t any real security impact."

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Cesanta Mongooseos Mjs

    APP
    Cesanta
    1.26
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2023-50044CRITICAL9.8PL ✓same vendor

Cesanta MJS: out-of-bounds read w funkcji getprop_builtin_foreign

CVE-2023-43338CRITICAL9.8PL ✓same vendor

Przejęcie wskaźnika funkcji w Cesanta MJS umożliwiające RCE

CVE-2022-25299CRITICAL9.8PL ✓same vendor

Zapis plików poza docelowym folderem w Cesanta Mongoose (mg_http_upload)

CVE-2021-26528CRITICAL9.1PL ✓same vendor

Zapis poza granicami pamięci (OOB write) w Cesanta Mongoose HTTP server 7.0

CVE-2021-26529CRITICAL9.1PL ✓same vendor

Zapis poza granicami bufora (OOB write) w Cesanta Mongoose HTTPS — mg_tls_init