CVE-2018-1000655

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
20/08/2018
Last modified:
25/10/2018

Description

Jsish version 2.4.65 contains a CWE-476: NULL Pointer Dereference vulnerability in Function jsi_ValueCopyMove from jsiValue.c:240 that can result in Crash due to segmentation fault. This attack appear to be exploitable via a crafted javascript code. This vulnerability appears to have been fixed in 2.4.67.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jsish:jsish:2.4.65:*:*:*:*:*:*:*