First published: Wed May 18 2022(Updated: )
compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a different issue than CVE-2019-11413.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex MuJS | <=1.2.0 | |
Debian Debian Linux | =11.0 | |
Fedoraproject Fedora | =37 | |
debian/mujs | 1.1.0-1+deb11u3 1.1.0-1+deb11u2 1.3.2-1 1.3.3-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30974 is a vulnerability in Artifex MuJS through version 1.2.0 that results in stack consumption due to unlimited recursion in the compile function of regexp.c.
CVE-2022-30974 has a severity rating of medium, with a CVSS score of 5.5.
Artifex MuJS versions up to and including 1.2.0 are affected by CVE-2022-30974, as well as Debian Linux 11.0 and Fedora 37.
To fix CVE-2022-30974, it is recommended to update Artifex MuJS to a version higher than 1.2.0.
You can find more information about CVE-2022-30974 on the following references: [GitHub Issue](https://github.com/ccxvii/mujs/issues/162), [Fedora Mailing List](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MC6PLHTXHZ7GW7QQGTLBHLXL47UHTHXO/), [Debian Security Advisory](https://www.debian.org/security/2022/dsa-5291).