CVE-2017-5628: Integer Overflow
An issue was discovered in Artifex Software, Inc. MuJS before 8f62ea10a0af68e56d5c00720523ebcba13c2e6a. The MakeDay function in jsdate.c does not validate the month, leading to an integer overflow when parsing a specially crafted JS file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5628?
CVE-2017-5628 has a severity rating that is considered high due to the potential for integer overflow vulnerabilities.
How do I fix CVE-2017-5628?
To mitigate CVE-2017-5628, it is recommended to update to a version of MuJS released after January 24, 2017.
What types of attacks can exploit CVE-2017-5628?
CVE-2017-5628 can be exploited through specially crafted JavaScript files that trigger the integer overflow within the MakeDay function.
What systems are affected by CVE-2017-5628?
CVE-2017-5628 affects versions of Artifex MuJS prior to January 24, 2017.
What should I do if I cannot update my software to fix CVE-2017-5628?
If you cannot update, consider applying additional security controls to restrict the execution of potentially unsafe JavaScript files.