Vulnerability Description
jsish version 2.4.67 contains a CWE-476: NULL Pointer Dereference vulnerability in Jsi_LogMsg (jsiUtils.c:196) that can result in Crash due to segmentation fault. This attack appear to be exploitable via the victim executing specially crafted javascript code. This vulnerability appears to have been fixed in 2.4.69.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jsish | Jsish | 2.4.67 |
Related Weaknesses (CWE)
References
- https://jsish.org/fossil/jsi/tktview/2adeb066894695b38309d92771aea11c8e0a56a8Vendor Advisory
- https://jsish.org/fossil/jsi/tktview/2adeb066894695b38309d92771aea11c8e0a56a8Vendor Advisory
FAQ
What is CVE-2018-1000661?
CVE-2018-1000661 is a vulnerability with a CVSS score of 6.5 (MEDIUM). jsish version 2.4.67 contains a CWE-476: NULL Pointer Dereference vulnerability in Jsi_LogMsg (jsiUtils.c:196) that can result in Crash due to segmentation fault. This attack appear to be exploitable ...
How severe is CVE-2018-1000661?
CVE-2018-1000661 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1000661?
Check the references section above for vendor advisories and patch information. Affected products include: Jsish Jsish.