CVE-2023-29458: Duktape 2.6 bug crashes JavaScript putting too many values in valstack.
Published Jul 13, 2023
·Updated
Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is an 3rd-party solution that we use.
Affected Software
3 affected components
Zabbix Zabbix=5.0.34
Zabbix Zabbix=6.0.17
Zabbix Zabbix=6.4.2
Event History
Jul 13, 2023
CVE Published
via MITRE·09:33 AM
Data Sourced
via MITRE·09:33 AM
DescriptionSeverityWeakness
Data Sourced
10:15 AM
Description
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-29458?
CVE-2023-29458 is a vulnerability in Duktape, a 3rd-party embeddable JavaScript engine, which can cause a crash when adding too many values in valstack.
2
How does CVE-2023-29458 affect Zabbix?
CVE-2023-29458 affects Zabbix versions 5.0.34, 6.0.17, and 6.4.2.
3
How severe is CVE-2023-29458?
CVE-2023-29458 has a severity rating of 7.5 (high).
4
Is there a fix available for CVE-2023-29458?
There is no known fix available for CVE-2023-29458 at the moment.
5
Where can I find more information about CVE-2023-29458?
More information about CVE-2023-29458 can be found at the following reference link: [here](https://support.zabbix.com/browse/ZBX-22989)