CVE-2019-12207: Critical severity f5 njs vulnerability
Published May 20, 2019
·Updated
njs through 0.3.1, used in NGINX, has a heap-based buffer over-read in nxtutf8decode in nxt/nxtutf8.c.
Affected Software
1 affected component
F5 Njs<=0.3.1
Event History
May 20, 2019
CVE Published
via MITRE·01:28 PM
Data Sourced
via MITRE·01:28 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-12207.
2
What is the severity of CVE-2019-12207?
The severity of CVE-2019-12207 is critical with a severity value of 9.8.
3
Which software is affected by CVE-2019-12207?
The software affected by CVE-2019-12207 is NGINX with njs version 0.3.1.
4
What is the CWE ID associated with CVE-2019-12207?
The CWE ID associated with CVE-2019-12207 is CWE-125.
5
Is there a fix available for CVE-2019-12207?
Yes, a fix is available for CVE-2019-12207. It is recommended to update the affected software to a version that includes the fix.