CyberRota Analysis
AI-GeneratedThe vulnerability affects Espruino 2v29 on 64-bit builds, specifically in the JavaScript error stack-trace handling, where a stack-based buffer overflow can be triggered by malicious JavaScript input. This flaw allows remote attackers to overwrite adjacent stack memory, potentially leading to arbitrary code execution or crashes. Organizations using this version of Espruino should prioritize remediation to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-bit builds. A remote attacker can supply JavaScript input that triggers an exception and reaches jslPrintTokenLineMarker(), which passes the address of a 4-byte int column variable to jsvGetLineAndCol() as a size_t pointer. jsvGetLineAndCol() performs an 8-byte write through the mismatched pointer, overwriting adjacent stack memory.