NA

CVE-2022-44789

Published: 23/11/2022 Updated: 07/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 up to and including 1.3.x prior to 1.3.2 allows an malicious user to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

artifex mujs

debian debian linux 11.0

fedoraproject fedora 37

Vendor Advisories

Debian Bug report logs - #1024769 mujs: CVE-2022-44789 Package: src:mujs; Maintainer for src:mujs is Bastian Germann <bage@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 24 Nov 2022 15:18:01 UTC Severity: important Tags: security, upstream Found in version mujs/130-1 Fixed in version ...
Multiple security issues were discovered in MuJS, a lightweight JavaScript interpreter, which could result in denial of service and potentially the execution of arbitrary code For the stable distribution (bullseye), these problems have been fixed in version 110-1+deb11u2 We recommend that you upgrade your mujs packages For the detailed securit ...

Github Repositories

CVE-2022-44789 Files: PublicReferenceURLtxt: public reference for CVE writeupmd: Writeup + exploit attachment: Vulnerable MuJS version + sample exploit