First published: Thu May 09 2019(Updated: )
njs through 0.3.1, used in NGINX, has a segmentation fault in String.prototype.toBytes for negative arguments, related to nxt_utf8_next in nxt/nxt_utf8.h and njs_string_offset in njs/njs_string.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Njs | <=0.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-11837.
The severity of CVE-2019-11837 is high with a score of 7.5.
The affected software for CVE-2019-11837 is F5 Njs version up to and including 0.3.1.
The CWE ID for CVE-2019-11837 is CWE-189.
Yes, a fix is available, and it is recommended to update to a version of F5 Njs that is later than 0.3.1.