CVE-2021-33797: Buffer Overflow
Published Apr 17, 2023
·Updated
Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when jsstrtod() reads in floating point exponent, which leads to a buffer overflow in the pointer d.
Affected Software
1 affected component
Artifex MuJS>=1.0.1<=1.1.1
Remediation
Event History
Apr 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this buffer overflow?
The vulnerability ID for this buffer overflow is CVE-2021-33797.
2
What is the severity of CVE-2021-33797?
CVE-2021-33797 has a severity rating of 9.8 (critical).
3
Which software versions are affected by CVE-2021-33797?
Versions 1.0.1 to 1.1.1 of Artifex MuJS are affected by CVE-2021-33797.
4
How does the buffer overflow in CVE-2021-33797 occur?
The buffer overflow in CVE-2021-33797 occurs due to an integer overflow when reading the floating point exponent in js_strtod().
5
Are there any fixes or patches available for CVE-2021-33797?
The latest version of Artifex MuJS (1.1.2 or later) contains a fix for the buffer overflow vulnerability CVE-2021-33797.