#VU28486 NULL pointer dereference in JerryScript - CVE-2020-13649
Published: June 1, 2020 / Updated: January 22, 2021
JerryScript
JerryScript
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error during certain out-of-memory conditions in the "parser/js/js-scanner.c" file, as demonstrated by a "scanner_reverse_info_list" NULL pointer dereference and a "scanner_scan_all assertion" failure. A remote attacker can perform a denial of service (DoS) attack.