CVE-2019-12206: Buffer Overflow
Published May 20, 2019
·Updated
njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in nxtutf8encode in nxtutf8.c.
Affected Software
1 affected component
F5 Njs<=0.3.1
Event History
May 20, 2019
CVE Published
via MITRE·01:28 PM
Data Sourced
via MITRE·01:28 PM
Description
Frequently Asked Questions
1
What is CVE-2019-12206?
CVE-2019-12206 is a vulnerability in njs, a JavaScript/ECMAScript engine used in NGINX, that allows a heap-based buffer overflow.
2
What is the severity of CVE-2019-12206?
The severity of CVE-2019-12206 is critical, with a severity value of 9.8.
3
How does CVE-2019-12206 affect NGINX?
CVE-2019-12206 affects NGINX as it uses njs as its JavaScript/ECMAScript engine.
4
How can I fix CVE-2019-12206?
To fix CVE-2019-12206, update to njs version 0.3.2 or later, which includes a patch for the vulnerability.
5
Where can I find more information about CVE-2019-12206?
You can find more information about CVE-2019-12206 at the following URL: https://github.com/nginx/njs/issues/162.