Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS before commit b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e allows attackers to cause a denial of service (application crash) via a crafted regular expression.
2017-02-03T15:59:00.790
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | fedoraproject | fedora | 23 | Yes |
Operating System | fedoraproject | fedora | 24 | Yes |
Operating System | fedoraproject | fedora | 25 | Yes |
Application | artifex | mujs | ≤ 2016-10-31 | Yes |