An issue was discovered in Artifex MuJS 1.0.5. The Number#toFixed() and numtostr implementations in jsnumber.c have a stack-based buffer overflow.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11411.json"
[
{
"target": {
"file": "jsnumber.c"
},
"id": "CVE-2019-11411-3467b92d",
"deprecated": false,
"signature_type": "Line",
"source": "https://github.com/ccxvii/mujs/commit/da632ca08f240590d2dec786722ed08486ce1be6",
"signature_version": "v1",
"digest": {
"line_hashes": [
"112303878148857575785563481959477582007",
"60656370197029655759566521420103616566",
"205932765757000462016086469228924002360",
"107315345907930435961402704420918512444",
"243442958124553229385940072060399894889",
"301203222834055025393008747670242060748",
"200431191256156287337465825434301386777",
"188942930420120263149313308069143455309",
"315093583428943497174408952091624801672",
"174722348540470695946555958085764595912",
"47032511159806869306578183917337519394",
"42214551393220435553945383601346391240"
],
"threshold": 0.9
}
},
{
"target": {
"function": "numtostr",
"file": "jsnumber.c"
},
"id": "CVE-2019-11411-41a1cf43",
"deprecated": false,
"signature_type": "Function",
"source": "https://github.com/ccxvii/mujs/commit/da632ca08f240590d2dec786722ed08486ce1be6",
"signature_version": "v1",
"digest": {
"function_hash": "177500532951410328270904823884242678146",
"length": 305.0
}
},
{
"target": {
"function": "Np_toString",
"file": "jsnumber.c"
},
"id": "CVE-2019-11411-54f554a4",
"deprecated": false,
"signature_type": "Function",
"source": "https://github.com/ccxvii/mujs/commit/da632ca08f240590d2dec786722ed08486ce1be6",
"signature_version": "v1",
"digest": {
"function_hash": "32606403519578985253964924652472965438",
"length": 1863.0
}
}
]