S-Lang 2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf().
The vulnerability consists of invoking an improper arithmetic operation within the tt_sprintf() function of the S-Lang 2.3.2 library. The error classified as CWE-703 (improper handling of exceptions or errors) suggests that the application does not properly handle invalid arithmetic conditions. An attacker can supply appropriately crafted input data that triggers this exception remotely, without the need for authentication.
Exploitation of the vulnerability may lead to denial of service (DoS) through a crash of an application using the S-Lang library, and potentially to unauthorized data disclosure (high confidentiality according to CVSS vector). The vulnerability is remotely accessible without authentication, which significantly increases the risk of its exploitation.
Patches available from the vendor should be applied in accordance with the references (slang-users and full-disclosure mailing lists). It is recommended to monitor official Jedsoft channels at lists.jedsoft.org for information about available updates.
Jedsoft S-Lang version 2.3.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HJedsoft S Lang
APPJedsoft2.3.2