CVE-2022-30974: Medium severity mujs vulnerability
compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a different issue than CVE-2019-11413.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-30974?
CVE-2022-30974 is a vulnerability in Artifex MuJS through version 1.2.0 that results in stack consumption due to unlimited recursion in the compile function of regexp.c.
What is the severity of CVE-2022-30974?
CVE-2022-30974 has a severity rating of medium, with a CVSS score of 5.5.
Which software versions are affected by CVE-2022-30974?
Artifex MuJS versions up to and including 1.2.0 are affected by CVE-2022-30974, as well as Debian Linux 11.0 and Fedora 37.
How can I fix CVE-2022-30974?
To fix CVE-2022-30974, it is recommended to update Artifex MuJS to a version higher than 1.2.0.
Where can I find more information about CVE-2022-30974?
You can find more information about CVE-2022-30974 on the following references: [GitHub Issue](https://github.com/ccxvii/mujs/issues/162), [Fedora Mailing List](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MC6PLHTXHZ7GW7QQGTLBHLXL47UHTHXO/), [Debian Security Advisory](https://www.debian.org/security/2022/dsa-5291).