CVE-2018-11593: Buffer Overflow
Espruino before 1.99 allows attackers to cause a denial of service (application crash) and potential Information Disclosure with a user crafted input file via a Buffer Overflow during syntax parsing because strncpy is misused in jslex.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-11593?
CVE-2018-11593 is a vulnerability that allows attackers to cause a denial of service (application crash) and potential information disclosure in Espruino versions before 1.99.
How does CVE-2018-11593 affect Espruino?
CVE-2018-11593 affects Espruino versions before 1.99 by allowing attackers to cause a denial of service and potential information disclosure through a buffer overflow during syntax parsing.
How severe is CVE-2018-11593?
CVE-2018-11593 has a severity rating of 7.1 (high).
How can I fix CVE-2018-11593?
To fix CVE-2018-11593, you should update Espruino to version 1.99 or newer.
Where can I find more information about CVE-2018-11593?
You can find more information about CVE-2018-11593 at the following references: [link 1], [link 2], [link 3].