Duktape v2.99.99 was discovered to contain a SEGV vulnerability via the component duk_push_tval in duktape/duk_api_stack.c.
The product does not release or incorrectly releases a resource before it is made available for re-use.
Link | Tags |
---|---|
https://github.com/svaarala/duktape/issues/2448 | patch exploit third party advisory issue tracking |
https://lists.debian.org/debian-lts-announce/2023/03/msg00033.html | mailing list |