CVE-2016-9108: Integer Overflow
Published Feb 3, 2017
·Updated
Integer overflow in the jsregcomp function in regexp.c in Artifex Software, Inc. MuJS before commit b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e allows attackers to cause a denial of service (application crash) via a crafted regular expression.
Affected Software
4 affected components
Fedoraproject Fedora=23
Fedoraproject Fedora=24
Fedoraproject Fedora=25
Artifex MuJS<=2016-10-31
Event History
Feb 3, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9108?
CVE-2016-9108 has been classified as a high severity vulnerability due to its potential to cause application crashes.
2
How do I fix CVE-2016-9108?
To fix CVE-2016-9108, update your MuJS versions to a release after October 31, 2016, or apply any available patches.
3
What systems are affected by CVE-2016-9108?
CVE-2016-9108 affects Fedora versions 23, 24, and 25, as well as MuJS versions up to and including 2016-10-31.
4
What type of attack does CVE-2016-9108 enable?
CVE-2016-9108 enables denial of service attacks through crafted regular expressions.
5
Who is responsible for the CVE-2016-9108 vulnerability?
CVE-2016-9108 was identified in the MuJS implementation by Artifex Software, Inc.