CVE-2020-14163
Summary
| CVE | CVE-2020-14163 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-15 21:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An issue was discovered in ecma/operations/ecma-container-object.c in JerryScript 2.2.0. Operations with key/value pairs did not consider the case where garbage collection is triggered after the key operation but before the value operation, as demonstrated by improper read access to memory in ecma_gc_set_object_visited in ecma/base/ecma-gc.c. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jerryscript | Jerryscript | 2.2.0 | All | All | All |
| Application | Jerryscript | Jerryscript | 2.2.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Memory corruption in ecma_gc_set_object_visited (jerry-core/ecma/base/ecma-gc.c:85) · Issue #3804 · jerryscript-project/jerryscript · GitHub | MISC | github.com | Third Party Advisory |
| Fix adding entries to the internal buffer of a Map object (#3805) · jerryscript-project/jerryscript@c2b6621 · GitHub | MISC | github.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.