CVE-2018-11590: Integer Overflow
Published May 31, 2018
·Updated
Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via an integer overflow during syntax parsing. This was addressed by fixing stack size detection on Linux in jsutils.c.
Affected Software
1 affected component
Espruino Espruino<1.99
Remediation
Event History
May 31, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-11590?
CVE-2018-11590 is a vulnerability in Espruino that allows attackers to cause a denial of service (application crash) by exploiting an integer overflow during syntax parsing.
2
How severe is CVE-2018-11590?
CVE-2018-11590 has a severity rating of 5.5, which is considered medium.
3
Which software versions are affected by CVE-2018-11590?
Espruino versions up to and excluding 1.99 are affected by CVE-2018-11590.
4
How can I fix CVE-2018-11590?
To fix CVE-2018-11590, you should update Espruino to version 1.99 or higher.
5
Where can I find more information about CVE-2018-11590?
You can find more information about CVE-2018-11590 on the following references: [link1], [link2], [link3].