NULL Pointer Dereference Affecting mujs package, versions [0,]
Snyk CVSS
Attack Complexity
Low
Availability
High
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.08% (34th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-UNMANAGED-MUJS-2833365
- published 18 May 2022
- disclosed 18 May 2022
- credit Han Zheng (@kdsjZh), NCNIPC of China, Hexhive
Introduced: 18 May 2022
CVE-2022-30975 Open this link in a new tabHow to fix?
There is no fixed version for mujs
.
Overview
Affected versions of this package are vulnerable to NULL Pointer Dereference in jsP_dumpsyntax
in jsdump.c
, leading to a crash with crafted input.