First published: Wed Nov 23 2022(Updated: )
A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mujs | 1.1.0-1+deb11u3 1.1.0-1+deb11u2 1.3.2-1 1.3.3-2 | |
Artifex MuJS | >=1.0.0<1.3.2 | |
Debian Debian Linux | =11.0 | |
Fedoraproject Fedora | =37 | |
>=1.0.0<1.3.2 | ||
=11.0 | ||
=37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-44789 is a logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS that allows an attacker to achieve remote code execution through memory corruption.
The severity level of CVE-2022-44789 is high with a severity value of 8.8.
To fix CVE-2022-44789, you should update to Artifex MuJS version 1.3.2 or later.
You can find more information about CVE-2022-44789 in the following references: [link1], [link2], [link3].