-
Notifications
You must be signed in to change notification settings - Fork 90
Open
Description
Enviroment
operating system: ubuntu18.04
compile command: make
test command: ./run_tests poc
poc:
https://drive.google.com/open?id=1jhNSWmb-SeA6K4xDWQCEhaJFts7E3iOa
vulnerability description:
CTinyJS :: expression has a problem. On the TinyJS.cpp + 1754 line, a null pointer reference is triggered, as shown in the figure:

The reason for the vulnerability is that when a temporary assignment variable a is generated, it is not verified whether a is empty, and then a-> var refers to a, which causes the vulnerability.
PoC construction
Metadata
Metadata
Assignees
Labels
No labels
