First published: Thu Jun 10 2021(Updated: )
There is a stack-overflow at ecma-regexp-object.c:535 in ecma_regexp_match in JerryScript 2.2.0.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JerryScript | =2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23306 has been classified as a potentially critical vulnerability due to the risk of a stack overflow.
To fix CVE-2020-23306, upgrade to a version of JerryScript that is later than 2.2.0, where the vulnerability has been addressed.
CVE-2020-23306 specifically affects JerryScript version 2.2.0.
CVE-2020-23306 impacts the ecma_regexp_match function in the ecma-regexp-object.c file of JerryScript.
Exploitation of CVE-2020-23306 could lead to application crashes or arbitrary code execution due to the stack overflow.