CRITICAL🇵🇱 Wersja polska

CVE-2023-45929

CVSS 9.1v3.1pub. 2024-03-27upd. 2025-05-30

S-Lang 2.3.2 was discovered to contain a segmentation fault via the function fixup_tgetstr().

🤖 AI Analysis
How it works

The vulnerability results from improper buffer handling in the fixup_tgetstr() function of the S-Lang library. Lack of proper buffer boundary validation (classic buffer overflow, CWE-120) enables triggering a segmentation fault. An attacker can remotely cause an application using this library to crash, and depending on the context, potentially gain unauthorized access to data in memory.

Impact

An attacker can cause unauthorized data access (confidentiality breach) and trigger an application crash resulting in denial of service (availability breach). The attack vector is network-based and does not require authentication or user interaction.

Mitigation & patch

Apply patches available from the vendor according to the references provided. It is recommended to monitor the slang-users mailing list (lists.jedsoft.org) and update to a version where the bug has been fixed. Until the fix is implemented, consider restricting network access to applications using the S-Lang library.

Who is affected

Jedsoft S-Lang version 2.3.2. Other versions may also be vulnerable – check the vendor references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • Jedsoft S Lang

    APP
    Jedsoft
    2.3.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-45927CRITICAL9.1PL ✓same product

Wyjątek arytmetyczny w S-Lang 2.3.2 — funkcja tt_sprintf()