First published: Mon Nov 27 2017(Updated: )
math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.
Credit: josh@bress.net
Affected Software | Affected Version | How to fix |
---|---|---|
Math.js | <=3.17.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1001002 is considered a high severity vulnerability due to its potential for arbitrary code execution.
To fix CVE-2017-1001002, upgrade your version of math.js to 3.17.0 or higher.
CVE-2017-1001002 affects all versions of math.js prior to 3.17.0.
CVE-2017-1001002 is an arbitrary code execution vulnerability that arises in the JavaScript engine.
Yes, CVE-2017-1001002 is considered easily exploitable if a malicious actor can trigger typed function creation with crafted names.