CVE-2020-1057

Improper Restriction of Operations within the Bounds of a Memory Buffer in nuget/Microsoft.ChakraCore

Identifiers

CVE-2020-1057

Package Slug

nuget/Microsoft.ChakraCore

Vulnerability

Improper Restriction of Operations within the Bounds of a Memory Buffer

Description

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1172, CVE-2020-1180.

Affected Versions

All versions before 1.11.22

Solution

Upgrade to version 1.11.22 or above.

Last Modified

2020-09-15

source