First published: Wed May 10 2023(Updated: )
Jerryscript 3.0.0(commit 1a2c047) was discovered to contain a heap-buffer-overflow via the component lexer_compare_identifier_to_chars at /jerry-core/parser/js/js-lexer.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jerryscript Jerryscript | =3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-31906 is high with a severity value of 7.8 (out of 10).
To fix the heap buffer overflow vulnerability in Jerryscript 3.0.0 (CVE-2023-31906), update to a version that has addressed the issue or apply any available patches from the vendor.
The affected software version of CVE-2023-31906 is Jerryscript 3.0.0.
The CWE of CVE-2023-31906 is CWE-787 (Out-of-bounds Write).
More information about CVE-2023-31906 can be found at the following reference link: [GitHub Issue](https://github.com/jerryscript-project/jerryscript/issues/5066).