CVE-2019-12798Incorrect Regular Expression in Mujs

Severity
9.8CRITICALNVD
EPSS
0.4%
top 37.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 13
Latest updateMay 24

Description

An issue was discovered in Artifex MuJS 1.0.5. regcompx in regexp.c does not restrict regular expression program size, leading to an overflow of the parsed syntax list size.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDartifex/mujs1.0.5

🔴Vulnerability Details

2
GHSA
GHSA-pccm-w2w7-v4p2: An issue was discovered in Artifex MuJS 12022-05-24
CVEList
CVE-2019-12798: An issue was discovered in Artifex MuJS 12019-06-13

📋Vendor Advisories

1
Debian
CVE-2019-12798: mujs - An issue was discovered in Artifex MuJS 1.0.5. regcompx in regexp.c does not res...2019
CVE-2019-12798 — Incorrect Regular Expression in Mujs | cvebase