CVE-2022-25465: Buffer Overflow
Published Mar 5, 2022
·Updated
Espruino 2v11 release was discovered to contain a stack buffer overflow via src/jsvar.c in jsvGetNextSibling.
Affected Software
1 affected component
Espruino Espruino=2.11
Event History
Mar 5, 2022
CVE Published
via MITRE·01:01 AM
Data Sourced
via MITRE·01:01 AM
Description
Frequently Asked Questions
1
What is CVE-2022-25465?
CVE-2022-25465 is a stack buffer overflow vulnerability in Espruino version 2.11.
2
What is the severity of CVE-2022-25465?
CVE-2022-25465 has a severity score of 7.8 (high).
3
How does CVE-2022-25465 occur?
CVE-2022-25465 occurs due to a stack buffer overflow in src/jsvar.c while using the jsvGetNextSibling function in Espruino version 2.11.
4
What software is affected by CVE-2022-25465?
Espruino version 2.11 is affected by CVE-2022-25465.
5
Is there a fix available for CVE-2022-25465?
At the moment, there is no official fix available for CVE-2022-25465. It is recommended to follow the references provided for any updates.