First published: Tue Jul 23 2019(Updated: )
Jsish 2.4.77 2.0477 is affected by: Use After Free. The impact is: denial of service. The component is: function Jsi_ObjFree (jsiObj.c:230). The attack vector is: executing crafted javascript code. The fixed version is: 2.4.78.
Credit: josh@bress.net
Affected Software | Affected Version | How to fix |
---|---|---|
Jsish Jsish | =2.4.77_2.0477 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1010170 is a vulnerability affecting Jsish version 2.4.77_2.0477, due to a use after free issue in the Jsi_ObjFree function.
The impact of CVE-2019-1010170 is a denial of service.
An attacker can exploit CVE-2019-1010170 by executing crafted JavaScript code.
To fix CVE-2019-1010170, update Jsish to version 2.4.78, which contains the necessary fix.
More information about CVE-2019-1010170 can be found at https://jsish.org/fossil/jsi/tktview/870f496bb8a707491df8026e2ff78b33a5cf44c1.