CVE-2016-7504: Use After Free
A use-after-free vulnerability was observed in RptoString function of Artifex Software, Inc. MuJS before 5c337af4b3df80cf967e4f9f6a21522de84b392a. A successful exploitation of this issue can lead to code execution or denial of service condition.
Other sources
Mujs received multiple CVEs for security issues.
CVE-2016-9108: Integer overflow and crash parsing regex in mujs
http://seclists.org/oss-sec/2016/q4/275
CVE-2016-9109: Incomplete fix for CVE-2016-7563
http://seclists.org/oss-sec/2016/q4/276
CVE-2016-7506: OOB read vulnerability in Spreplaceregexp function
http://bugs.ghostscript.com/showbug.cgi?id=697141
CVE-2016-7505: Buffer overflow in divby function
http://bugs.ghostscript.com/showbug.cgi?id=697140
CVE-2016-7504: Use-after-free in RptoString function
http://bugs.ghostscript.com/showbug.cgi?id=697142
CVE-2016-9017: OOB read in jsCdumpfunction function
http://bugs.ghostscript.com/showbug.cgi?id=697171
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7504?
CVE-2016-7504 has a high severity due to its potential for code execution and denial of service.
How do I fix CVE-2016-7504?
The best way to fix CVE-2016-7504 is to update to the version of MuJS that addresses this vulnerability after 5000749f5afe3b956fc916e407309de840997f4a.
What versions of MuJS are affected by CVE-2016-7504?
CVE-2016-7504 affects all versions of MuJS prior to 5000749f5afe3b956fc916e407309de840997f4a.
Can CVE-2016-7504 be exploited remotely?
Yes, CVE-2016-7504 can potentially be exploited remotely if the vulnerable MuJS version is accessible over a network.
What are the consequences of exploiting CVE-2016-7504?
Exploiting CVE-2016-7504 can lead to arbitrary code execution or a denial of service condition.