CVE-2023-29570: Medium severity mjs vulnerability
Published Apr 24, 2023
·Updated
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjsfficbfree at src/mjsffi.c. This vulnerability can lead to a Denial of Service (DoS).
Affected Software
1 affected component
Cesanta mJS=2.20.0
Event History
Apr 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-29570?
CVE-2023-29570 is a vulnerability in Cesanta MJS v2.20.0 that can lead to a Denial of Service (DoS) attack.
2
How severe is CVE-2023-29570?
CVE-2023-29570 has a severity rating of medium with a CVSS score of 5.5.
3
What software versions are affected by CVE-2023-29570?
CVE-2023-29570 affects Cesanta MJS v2.20.0.
4
How can CVE-2023-29570 be exploited?
CVE-2023-29570 can be exploited by triggering a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c.
5
Is there a fix for CVE-2023-29570?
Yes, the fix for CVE-2023-29570 can be found in the GitHub issue: https://github.com/cesanta/mjs/issues/240.