In mjs_json.c in Cesanta MongooseOS mJS 1.26, a...
Critical severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Mar 30, 2024
Description
Published by the National Vulnerability Database
Apr 29, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Mar 30, 2024
In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_json_parse, which can potentially lead to redirection of control flow.
References