First published: Thu May 09 2019(Updated: )
njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.push after a resize, related to njs_array_prototype_push in njs/njs_array.c, because of njs_array_expand size mishandling.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Njs | <=0.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-11839.
The F5 Njs software up to and including version 0.3.1 is affected by CVE-2019-11839.
CVE-2019-11839 has a severity rating of 9.8 (Critical).
The CWE ID for CVE-2019-11839 is CWE-119 and CWE-787.
Yes, you can find the reference link for CVE-2019-11839 at https://github.com/nginx/njs/issues/152.