An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the StringReplaceCmd function in the src/jsiChar.c file.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/pcmacdon/jsish/issues/14 | patch issue tracking exploit |
https://jsish.org/fossil/jsi2/tktview?name=3e211e44b1 | broken link |