CVE-2018-11595: Buffer Overflow
Published May 31, 2018
·Updated
Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Escalation of Privileges with a user crafted input file via a Buffer Overflow during syntax parsing, because strncat is misused.
Affected Software
1 affected component
Espruino Espruino<1.99
Remediation
Event History
May 31, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-11595.
2
What is the severity of CVE-2018-11595?
The severity of CVE-2018-11595 is high with a score of 7.8.
3
How does CVE-2018-11595 impact Espruino before version 1.99?
CVE-2018-11595 allows attackers to cause a denial of service (application crash) and a potential escalation of privileges with a user-crafted input file via a buffer overflow during syntax parsing.
4
How can I mitigate the risk of CVE-2018-11595?
To mitigate the risk of CVE-2018-11595, it is recommended to update Espruino to version 1.99 or higher.
5
Where can I find more information about CVE-2018-11595?
More information about CVE-2018-11595 can be found at the following references: [link1], [link2], [link3].