CVE-2022-30975: Null Pointer Dereference
Published May 18, 2022
·Updated
In Artifex MuJS through 1.2.0, jsPdumpsyntax in jsdump.c has a NULL pointer dereference, as demonstrated by mujs-pp.
Affected Software
4 affected componentsFixes available
debian/mujs
1.1.0-1+deb11u31.1.0-1+deb11u21.3.2-11.3.3-2
Artifex MuJS<=1.2.0
Debian Debian Linux=11.0
Fedoraproject Fedora=37
Remediation
Patch Available
Event History
May 18, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-30975.
2
What is the severity level of CVE-2022-30975?
CVE-2022-30975 has a severity level of 5.5 (medium).
3
What is the affected software for CVE-2022-30975?
The affected software for CVE-2022-30975 includes Artifex MuJS version 1.2.0, Debian Debian Linux version 11.0, and Fedoraproject Fedora version 37.
4
What is the description of CVE-2022-30975?
CVE-2022-30975 is a vulnerability in Artifex MuJS that allows for a NULL pointer dereference.
5
How do I fix CVE-2022-30975?
To fix CVE-2022-30975, it is recommended to update to a version that has the fix, such as Artifex MuJS version 1.3.2 or 1.3.3.