漏洞信息详情
JerryScript 安全漏洞
漏洞简介
JerryScript是JerryScript项目的一款轻量级的JavaScript引擎。
JerryScript vm/opcodes.c 2.2.0版本中存在安全漏洞,该漏洞允许攻击者通过控制寄存器来劫持控制流。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/jerryscript-project/jerryscript/commit/c09c2c5dd7144d97b8b32cc2697d5b04bb647e35
参考网址
来源:MISC
链接:https://github.com/jerryscript-project/jerryscript/pull/3867
来源:MISC
链接:https://github.com/jerryscript-project/jerryscript/issues/3860
来源:CONFIRM
链接:https://github.com/googleprojectzero/fuzzilli#JerryScript
来源:MISC
链接:https://github.com/jerryscript-project/jerryscript/issues/3858
来源:MISC
链接:https://github.com/jerryscript-project/jerryscript/issues/3859
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-13991
受影响实体
暂无
补丁
- JerryScript 安全漏洞的修复措施<!--2020-9-24-->
还没有评论,来说两句吧...