Severity
8.8HIGHNVD
EPSS
2.6%
top 14.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 23

Description

A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDartifex/mujs1.0.01.3.2
Debianartifex/mujs< 1.1.0-1+deb11u2+3

Also affects: Debian Linux 11.0, Fedora 37

Patches

🔴Vulnerability Details

3
CVEList
CVE-2022-44789: A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 12022-11-23
OSV
CVE-2022-44789: A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 12022-11-23
GHSA
GHSA-57j3-gx8q-fwcj: A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 12022-11-23

📋Vendor Advisories

1
Debian
CVE-2022-44789: mujs - A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1....2022
CVE-2022-44789 — Out-of-bounds Write in Artifex Mujs | cvebase