CVE-2019-11839: Buffer Overflow
Published May 9, 2019
·Updated
njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.push after a resize, related to njsarrayprototypepush in njs/njsarray.c, because of njsarrayexpand size mishandling.
Affected Software
1 affected component
F5 Njs<=0.3.1
Event History
May 9, 2019
CVE Published
via MITRE·01:07 PM
Data Sourced
via MITRE·01:07 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-11839.
2
What software is affected by CVE-2019-11839?
The F5 Njs software up to and including version 0.3.1 is affected by CVE-2019-11839.
3
What is the severity rating of CVE-2019-11839?
CVE-2019-11839 has a severity rating of 9.8 (Critical).
4
What is the CWE ID for CVE-2019-11839?
The CWE ID for CVE-2019-11839 is CWE-119 and CWE-787.
5
Is there a reference link available for CVE-2019-11839?
Yes, you can find the reference link for CVE-2019-11839 at https://github.com/nginx/njs/issues/152.