An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the Jsi_Strlen function in the src/jsiChar.c file.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://github.com/pcmacdon/jsish/issues/13 | patch issue tracking exploit |
https://jsish.org/fossil/jsi2/tktview?name=b6bb078e00 | broken link |