CVE-2019-11412: High severity mujs vulnerability
An issue was discovered in Artifex MuJS 1.0.5. jscompile.c can cause a denial of service (invalid stack-frame jump) because it lacks an ENDTRY opcode call.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-11412?
The severity of CVE-2019-11412 is high.
How does CVE-2019-11412 cause a denial of service?
CVE-2019-11412 causes a denial of service by triggering an invalid stack-frame jump in jscompile.c.
Which software versions are affected by CVE-2019-11412?
Artifex MuJS 1.0.5, Fedoraproject Fedora 31, Fedoraproject Fedora 32, and Fedoraproject Fedora 33 are affected by CVE-2019-11412.
Are there any references for CVE-2019-11412?
Yes, you can find more information about CVE-2019-11412 at the following references: [http://www.ghostscript.com/cgi-bin/findgit.cgi?1e5479084bc9852854feb1ba9bf68b52cd127e02](http://www.ghostscript.com/cgi-bin/findgit.cgi?1e5479084bc9852854feb1ba9bf68b52cd127e02), [http://www.securityfocus.com/bid/108093](http://www.securityfocus.com/bid/108093), [https://bugs.ghostscript.com/show_bug.cgi?id=700947](https://bugs.ghostscript.com/show_bug.cgi?id=700947)
Is there a fix available for CVE-2019-11412?
To fix CVE-2019-11412, you should update to a patched version of Artifex MuJS or Fedoraproject Fedora.