CVE-2016-10132
published 2017-03-24CVE-2016-10132: regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to regular…
PriorityP431high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.16%
80.1th percentile
regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to regular expression compilation.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mujs | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-29jw-cm22-w2mv: regexp
ghsa_unreviewed·2022-05-17
CVE-2016-10132 [HIGH] CWE-476 GHSA-29jw-cm22-w2mv: regexp
regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to regular expression compilation.
Debian
CVE-2016-10132: mujs - regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of se...
vendor_debian·2016·CVSS 7.5
CVE-2016-10132 [HIGH] CVE-2016-10132: mujs - regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of se...
regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to regular expression compilation.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-10132 CVE-2016-10133 CVE-2016-10141 CVE-2017-5627 CVE-2017-5628 mujs: Multiple security issues [fedora-all]
bugzilla·2017-01-13·CVSS 7.5
CVE-2016-10132 [HIGH] CVE-2016-10132 CVE-2016-10133 CVE-2016-10141 CVE-2017-5627 CVE-2017-5628 mujs: Multiple security issues [fedora-all]
CVE-2016-10132 CVE-2016-10133 CVE-2016-10141 CVE-2017-5627 CVE-2017-5628 mujs: Multiple security issues [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2016-10132 CVE-2016-10133 CVE-2016-10141 CVE-2017-5627 CVE-2017-5628 mujs: Multiple security issues
bugzilla·2017-01-13·CVSS 7.5
CVE-2016-10132 [HIGH] CVE-2016-10132 CVE-2016-10133 CVE-2016-10141 CVE-2017-5627 CVE-2017-5628 mujs: Multiple security issues
CVE-2016-10132 CVE-2016-10133 CVE-2016-10141 CVE-2017-5627 CVE-2017-5628 mujs: Multiple security issues
Two security issues received CVEs on oss-security.
1. Null pointer dereference in regexp.c - CVE-2016-10132
The return value from malloc is not properly checked before dereferencing it which can result in a crash.
https://bugs.ghostscript.com/show_bug.cgi?id=697381
http://git.ghostscript.com/?p=mujs.git;h=fd003eceda531e13fbdd1aeb6e9c73156496e569
2. Heap buffer overflow write in jsrun.c: js_stackoverflow() - CVE-2016-10133
There was a logical error in the code which can be used to trigger a heap overflow write.
https://bugs.ghostscript.com/show_bug.cgi?id=697401
http://git.ghostscript.com/?p=mujs.git;a=commit;h=77ab465f1c394bb77f00966cd950650f3f53cb24
Discussion:
Created mujs tra
http://git.ghostscript.com/?p=mujs.git%3Bh=fd003eceda531e13fbdd1aeb6e9c73156496e569http://www.openwall.com/lists/oss-security/2017/01/12/9http://www.openwall.com/lists/oss-security/2017/01/13/1https://bugs.ghostscript.com/show_bug.cgi?id=697381https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T3U5APFS3FEBOPXUJIFWBNU55PYR7ZBF/http://git.ghostscript.com/?p=mujs.git%3Bh=fd003eceda531e13fbdd1aeb6e9c73156496e569http://www.openwall.com/lists/oss-security/2017/01/12/9http://www.openwall.com/lists/oss-security/2017/01/13/1https://bugs.ghostscript.com/show_bug.cgi?id=697381https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T3U5APFS3FEBOPXUJIFWBNU55PYR7ZBF/
2017-03-24
Published