CVE-2019-11837: High severity f5 njs vulnerability
Published May 9, 2019
·Updated
njs through 0.3.1, used in NGINX, has a segmentation fault in String.prototype.toBytes for negative arguments, related to nxtutf8next in nxt/nxtutf8.h and njsstringoffset in njs/njsstring.c.
Affected Software
1 affected component
F5 Njs<=0.3.1
Event History
May 9, 2019
CVE Published
via MITRE·01:07 PM
Data Sourced
via MITRE·01:07 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2019-11837.
2
What is the severity of CVE-2019-11837?
The severity of CVE-2019-11837 is high with a score of 7.5.
3
What is the affected software for CVE-2019-11837?
The affected software for CVE-2019-11837 is F5 Njs version up to and including 0.3.1.
4
What is the CWE ID for this vulnerability?
The CWE ID for CVE-2019-11837 is CWE-189.
5
Is there a fix available for CVE-2019-11837?
Yes, a fix is available, and it is recommended to update to a version of F5 Njs that is later than 0.3.1.