Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Wed, 21 Sep 2016 19:01:23 +0800
From: Puzzor <>
Subject: CVE request - mujs Heap-Buffer-Overflow write and OOB Read


Two vulnerabilities were found in mujs latest version, and they have got

1. mujs str Out-of-Bound read 1 byte in function chartorune.

2. mujs "char *s" Heap overflow in Fp_toString at jsfunction.c:72

Please assign CVE-IDs for them.
The vulnerabilities were found by Shi Ji(@...zor)

Best regards,
Shi Ji(@...zor)

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ