CVE-2019-13617

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
16/07/2019
Last modified:
24/03/2022

Description

njs through 0.3.3, used in NGINX, has a heap-based buffer over-read in nxt_vsprintf in nxt/nxt_sprintf.c during error handling, as demonstrated by an njs_regexp_literal call that leads to an njs_parser_lexer_error call and then an njs_parser_scope_error call.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:njs:*:*:*:*:*:*:*:* 0.3.3 (including)