CRITICAL🇵🇱 Wersja polska

CVE-2023-45927

CVSS 9.1v3.1pub. 2024-03-27upd. 2025-11-04

S-Lang 2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf().

🤖 AI Analysis
How it works

The vulnerability consists of invoking an improper arithmetic operation within the tt_sprintf() function of the S-Lang 2.3.2 library. The error classified as CWE-703 (improper handling of exceptions or errors) suggests that the application does not properly handle invalid arithmetic conditions. An attacker can supply appropriately crafted input data that triggers this exception remotely, without the need for authentication.

Impact

Exploitation of the vulnerability may lead to denial of service (DoS) through a crash of an application using the S-Lang library, and potentially to unauthorized data disclosure (high confidentiality according to CVSS vector). The vulnerability is remotely accessible without authentication, which significantly increases the risk of its exploitation.

Mitigation & patch

Patches available from the vendor should be applied in accordance with the references (slang-users and full-disclosure mailing lists). It is recommended to monitor official Jedsoft channels at lists.jedsoft.org for information about available updates.

Who is affected

Jedsoft S-Lang version 2.3.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • Jedsoft S Lang

    APP
    Jedsoft
    2.3.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-45929CRITICAL9.1PL ✓same product

S-Lang 2.3.2: błąd segmentacji w funkcji fixup_tgetstr()