First published: Thu May 28 2020(Updated: )
parser/js/js-scanner.c in JerryScript 2.2.0 mishandles errors during certain out-of-memory conditions, as demonstrated by a scanner_reverse_info_list NULL pointer dereference and a scanner_scan_all assertion failure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JerryScript | =2.2.0 |
https://github.com/jerryscript-project/jerryscript/commit/69f8e78c2f8d562bd6d8002b5488f1662ac30d24
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13649 is classified as a low severity vulnerability due to its specific conditions triggering the issues.
To fix CVE-2020-13649, upgrade to a later version of JerryScript that addresses this vulnerability.
CVE-2020-13649 specifically affects JerryScript version 2.2.0.
Exploitation of CVE-2020-13649 may lead to application crashes due to NULL pointer dereferences.
Additional details about CVE-2020-13649 can be found in the JerryScript GitHub repository.