+33 (0)1 8695 8660

Vulnerability Details :

An issue was discovered in Artifex MuJS 1.0.5. The Number#toFixed() and numtostr implementations in jsnumber.c have a stack-based buffer overflow.
Publish Date : 2019-04-22 Last Update Date : 2019-04-22

- CVSS Scores & Vulnerability Types

CVSS Score
7.5
Confidentiality Impact Partial(There is considerable informational disclosure.)
Integrity Impact Partial(Modification of some system files or information is possible, but the attacker does not have control over what can be modified, or the scope of what the attacker can affect is limited.)
Availability Impact Partial(There is reduced performance or interruptions in resource availability.)
Access Complexity Low(Specialized access conditions or extenuating circumstances do not exist. Very little knowledge or skill is required to exploit. )
Authentication Not required(Authentication is not required to exploit the vulnerability.)
Gained Access None
Vulnerability Type(s) Overflow
CWE ID 119

- Products Affected By CVE-2019-11411

# Product Type Vendor Product Version Update Edition Language
1 Application Artifex Mujs 1.0.5 Version Details Vulnerabilities

- Number Of Affected Versions By Product

Vendor Product Vulnerable Versions
Artifex Mujs 1

- References For CVE-2019-11411

http://www.ghostscript.com/cgi-bin/findgit.cgi?da632ca08f240590d2dec786722ed08486ce1be6
https://bugs.ghostscript.com/show_bug.cgi?id=700938
https://github.com/ccxvii/mujs/commit/da632ca08f240590d2dec786722ed08486ce1be6

- Metasploit Modules Related To CVE-2019-11411

There are not any metasploit modules related to this CVE entry (Please visit www.metasploit.com for more information)


Newsletter Cybersécurité

Restez informé: recevez régulièrement les nouveautés et évènements en matière de cybersécurité et sécurité informatique.
En renseignant votre adresse email, vous acceptez de recevoir nos derniers articles de blog par courrier électronique et vous prenez connaissance de notre Politique de Confidentialité. Vous pouvez vous désinscrire à tout moment.

Notre expertise cybersécurité validée par de multiples certifications internationales

certifications sécurité informatique AKAOMA