quickjs-ng through 0.9.0 has an incorrect size...
Moderate severity
Unreviewed
Published
Apr 27, 2025
to the GitHub Advisory Database
•
Updated Apr 27, 2025
Description
Published by the National Vulnerability Database
Apr 27, 2025
Published to the GitHub Advisory Database
Apr 27, 2025
Last updated
Apr 27, 2025
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
References