An issue found in Jsish v.3.0.11 allows a remote attacker to cause a denial of service via the Jsi_ValueIsNumber function in ./src/jsiValue.c file.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/pcmacdon/jsish/issues/12 | patch issue tracking exploit |
https://jsish.org/fossil/jsi2/tktview?name=2ba1d89d32 | broken link |