CVE-2019-12208: Buffer Overflow
Published May 20, 2019
·Updated
njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in njsfunctionnativecall in njs/njsfunction.c.
Affected Software
1 affected component
F5 Njs<=0.3.1
Event History
May 20, 2019
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-12208.
2
What is the severity of CVE-2019-12208?
The severity of CVE-2019-12208 is critical (9.8).
3
What is the affected software for CVE-2019-12208?
The affected software for CVE-2019-12208 is F5 Njs up to version 0.3.1.
4
What is the CWE category of CVE-2019-12208?
The CWE category of CVE-2019-12208 is CWE-119 and CWE-787.
5
How can I mitigate the vulnerability in CVE-2019-12208?
To mitigate the vulnerability in CVE-2019-12208, update to a version of F5 Njs that is higher than 0.3.1.