CVE-2018-20201: High severity espruino vulnerability
Published Dec 18, 2018
·Updated
There is a stack-based buffer over-read in the jsfNameFromString function of jsflash.c in Espruino 2V00, leading to a denial of service or possibly unspecified other impact via a crafted js file.
Affected Software
1 affected component
Pur3 Espruino=2.00
Event History
Dec 18, 2018
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20201?
The severity of CVE-2018-20201 is classified as a denial of service vulnerability.
2
How do I fix CVE-2018-20201?
To fix CVE-2018-20201, upgrade to a patched version of Espruino that resolves the stack-based buffer over-read issue.
3
What causes the CVE-2018-20201 vulnerability?
CVE-2018-20201 is caused by a stack-based buffer over-read in the jsfNameFromString function within the Espruino firmware.
4
What are the potential impacts of CVE-2018-20201?
The potential impacts of CVE-2018-20201 include denial of service and possibly other unspecified consequences.
5
Which version of Espruino is affected by CVE-2018-20201?
CVE-2018-20201 specifically affects Espruino version 2.00.