CVE-2018-11592: Medium severity Espruino Espruino vulnerability
Espruino before 1.98 allows attackers to cause a denial of service (application crash) with a user crafted input file via an Out-of-bounds Read during syntax parsing in which certain height validation is missing in libs/graphics/jswrapgraphics.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-11592?
CVE-2018-11592 is a vulnerability in Espruino before version 1.98 that allows attackers to cause a denial of service (application crash) by exploiting an out-of-bounds read during syntax parsing.
How severe is CVE-2018-11592?
CVE-2018-11592 has a severity score of 5.5 (medium).
How can this vulnerability be exploited?
This vulnerability can be exploited by providing a user crafted input file that triggers an out-of-bounds read.
Is there a fix for CVE-2018-11592?
Yes, a fix for CVE-2018-11592 is available in Espruino version 1.98 and later.
Where can I find more information about CVE-2018-11592?
You can find more information about CVE-2018-11592 at the following references: [reference_1](https://github.com/espruino/Espruino/commit/8a44b04b584b3d3ab1cb68fed410f7ecb165e50e), [reference_2](https://github.com/espruino/Espruino/files/2015630/test_0.txt), [reference_3](https://github.com/espruino/Espruino/issues/1421).