CVE-2017-0223: Improper Restriction of Operations within the Bounds of a Memory Buffer
(updated )
A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka “Scripting Engine Memory Corruption Vulnerability”. This vulnerability is unique from CVE-2017-0252.
References
- github.com/Microsoft/ChakraCore/pull/2959
- github.com/advisories/GHSA-448h-7hmp-99fg
- github.com/chakra-core/ChakraCore/commit/f74773f4520adff6b70a7d445417aa9769f61fa6
- github.com/chakra-core/ChakraCore/pull/2959
- nvd.nist.gov/vuln/detail/CVE-2017-0223
- web.archive.org/web/20210124184849/http://www.securitytracker.com/id/1038425
Detect and mitigate CVE-2017-0223 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →