CVE-2019-11838: Buffer Overflow
Published May 9, 2019
·Updated
njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.splice after a resize, related to njsarrayprototypesplice in njs/njsarray.c, because of njsarrayexpand size mishandling.
Affected Software
1 affected component
F5 Njs<=0.3.1
Event History
May 9, 2019
CVE Published
via MITRE·01:07 PM
Data Sourced
via MITRE·01:07 PM
Description
Frequently Asked Questions
1
What is CVE-2019-11838?
CVE-2019-11838 is a vulnerability in njs, used in NGINX, which allows a heap-based buffer overflow in Array.prototype.splice after a resize, leading to potential code execution.
2
What is the severity of CVE-2019-11838?
CVE-2019-11838 has a severity rating of critical, with a CVSS score of 9.8.
3
How does CVE-2019-11838 affect F5 Njs?
CVE-2019-11838 affects F5 Njs version 0.3.1.
4
How can I fix CVE-2019-11838?
To fix CVE-2019-11838, update to a version of njs that is not affected by the vulnerability.
5
Where can I find more information about CVE-2019-11838?
More information about CVE-2019-11838 can be found at the following link: https://github.com/nginx/njs/issues/153.