CVE-2016-9108

HIGH

MuJS <b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e - DoS

Title source: llm
STIX 2.1

Description

Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS before commit b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e allows attackers to cause a denial of service (application crash) via a crafted regular expression.

References (6)

Core 6
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1390266
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/10/30/12
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96006

Scores

CVSS v3 7.5
EPSS 0.0150
EPSS Percentile 81.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-190
Status published
Products (4)
artifex/mujs < 2016-10-31
fedoraproject/fedora 23
fedoraproject/fedora 24
fedoraproject/fedora 25
Published Feb 03, 2017
Tracked Since Feb 18, 2026