Source: iotjs Version: 1.0+715-1 Severity: important Tags: security upstream Forwarded: https://github.com/jerryscript-project/jerryscript/issues/4244 X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org> Control: found -1 1.0-1
Hi, The following vulnerability was published for iotjs. Actually for embedded jerryscript, which seem still affected in up to the version included in 1.0+715-1. CVE-2020-29657[0]: | In JerryScript 2.3.0, there is an out-of-bounds read in | main_print_unhandled_exception in the main-utils.c file. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2020-29657 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29657 [1] https://github.com/jerryscript-project/jerryscript/issues/4244 Regards, Salvatore