Several security issues were fixed in MuJS.. ========================================================================== Ubuntu Security Notice USN-7575-1 June 18, 2025 mujs vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in MuJS. Software Description: - mujs: Lightweight Javascript interpreter Details: It was discovered that MuJS did not correctly handle try/finally statements, which could lead to a buffer overflow. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2021-45005) Han Zheng discovered that MuJS did not correctly handle recursion, which could lead to stack exhaustion. An attacker could possibly use this issue to cause a denial of service. (CVE-2022-30974) Han Zheng discovered that MuJS did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service. (CVE-2022-30975) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS libmujs-dev 1.1.3-3ubuntu0.1~esm1 Available with Ubuntu Pro libmujs1 1.1.3-3ubuntu0.1~esm1 Available with Ubuntu Pro mujs 1.1.3-3ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7575-1 CVE-2021-45005, CVE-2022-30974, CVE-2022-30975 . Multiple vulnerabilities in MuJS may result in service interruption or arbitrary code execution. An update is advised for Ubuntu 22.04 LTS.. MuJS Support Update, Ubuntu 22.04 Security Fix, Javascript Interpreter Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Multiple vulnerabilities have been discovered in mujs, the worst of which could lead to remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202405-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: mujs: Multiple Vulnerabilities Date: May 04, 2024 Bugs: #833453, #845399, #882775 ID: 202405-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in mujs, the worst of which could lead to remote code execution. Background ========== mujs is an embeddable Javascript interpreter in C. Affected packages ================= Package Vulnerable Unaffected ------------- ------------ ------------ dev-lang/mujs < 1.3.2 > = 1.3.2 Description =========== Multiple vulnerabilities have been discovered in mujs. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All mujs users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-lang/mujs-1.3.2" References ========== [ 1 ] CVE-2021-45005 https://nvd.nist.gov/vuln/detail/CVE-2021-45005 [ 2 ] CVE-2022-30974 https://nvd.nist.gov/vuln/detail/CVE-2022-30974 [ 3 ] CVE-2022-30975 https://nvd.nist.gov/vuln/detail/CVE-2022-30975 [ 4 ] CVE-2022-44789 https://nvd.nist.gov/vuln/detail/CVE-2022-44789 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202405-06 Concerns? ========= Security is a primary focus of GentooLinux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
- Fix CVE-2022-44789 (rhbz#2148261) - Fix CVE-2022-30975 (rhbz#2088596) - Fix CVE-2022-30974 (rhbz#2088591). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-c4b56e4400 2022-12-20 01:27:52.482891 --------------------------------------------------------------------------------Name : mujs Product : Fedora 37 Version : 1.3.2 Release : 1.fc37 URL : https://mujs.com/ Summary : An embeddable Javascript interpreter Description : MuJS is a lightweight Javascript interpreter designed for embedding in other software to extend them with scripting capabilities. --------------------------------------------------------------------------------Update Information: - Fix CVE-2022-44789 (rhbz#2148261) - Fix CVE-2022-30975 (rhbz#2088596) - Fix CVE-2022-30974 (rhbz#2088591) --------------------------------------------------------------------------------ChangeLog: * Thu Dec 1 2022 Alain Vigne 1.3.2-1 - upstream release 1.3.2 - Fix CVE-2022-44789 (rhbz#2148261) - Fix CVE-2022-30975 (rhbz#2088596) - Fix CVE-2022-30974 (rhbz#2088591) --------------------------------------------------------------------------------References: [ 1 ] Bug #2088590 - CVE-2022-30974 mujs: stack consumption because of unlimited recursion in compile() in regexp.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2088590 [ 2 ] Bug #2088594 - CVE-2022-30975 mujs: NULL pointer dereference in jsP_dumpsyntax() in jsdump.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2088594 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-c4b56e4400' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details onthe GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Multiple security issues were discovered in MuJS, a lightweight JavaScript interpreter, which could result in denial of service and potentially the execution of arbitrary code. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5291-1
Multiple vulnerabilities have been found in mujs, the worst of which could result in a Denial of Service condition.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202007-52 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: mujs: Multiple vulnerabilities Date: July 28, 2020 Bugs: #719248 ID: 202007-52 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in mujs, the worst of which could result in a Denial of Service condition. Background ========= mujs is an embeddable Javascript interpreter in C. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-lang/mujs < 1.0.6 > = 1.0.6 Description ========== Multiple vulnerabilities have been discovered in mujs. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All mujs users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-lang/mujs-" References ========= [ 1 ] CVE-2019-11411 https://nvd.nist.gov/vuln/detail/CVE-2019-11411 [ 2 ] CVE-2019-11412 https://nvd.nist.gov/vuln/detail/CVE-2019-11412 [ 3 ] CVE-2019-11413 https://nvd.nist.gov/vuln/detail/CVE-2019-11413 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202007-52 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Security fix for CVE-2018-5759.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-5b2e981f14 2018-02-14 17:26:16.387108 --------------------------------------------------------------------------------Name : mujs Product : Fedora 27 Version : 0 Release : 11.20180129git25821e6.fc27 URL : https://mujs.com/ Summary : An embeddable Javascript interpreter Description : MuJS is a lightweight Javascript interpreter designed for embedding in other software to extend them with scripting capabilities. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2018-5759. --------------------------------------------------------------------------------References: [ 1 ] Bug #1539514 - CVE-2018-5759 mujs: Improper management of AST depth in jsparse.c can allow a remote attacker to cause a denial of service via a crafted file https://bugzilla.redhat.com/show_bug.cgi?id=1539514 [ 2 ] Bug #1539847 - CVE-2018-6191 mujs: Interger overflow in js_strtod function in jsdtoa.c https://bugzilla.redhat.com/show_bug.cgi?id=1539847 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mujs' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2016-10132, CVE-2016-10133, CVE-2016-10141, CVE-2017-5627, CVE-2017-5628.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-624e2eeda0 2017-02-22 13:27:29.728941 -------------------------------------------------------------------------------- Name : mujs Product : Fedora 24 Version : 0 Release : 8.20170124git4006739.fc24 URL : https://mujs.com/ Summary : An embeddable Javascript interpreter Description : MuJS is a lightweight Javascript interpreter designed for embedding in other software to extend them with scripting capabilities. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-10132, CVE-2016-10133, CVE-2016-10141, CVE-2017-5627, CVE-2017-5628. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1412967 - CVE-2016-10132 CVE-2016-10133 CVE-2016-10141 CVE-2017-5627 CVE-2017-5628 mujs: Multiple security issues https://bugzilla.redhat.com/show_bug.cgi?id=1412967 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mujs' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2016-10132, CVE-2016-10133, CVE-2016-10141, CVE-2017-5627, CVE-2017-5628.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-dc6023e849 2017-02-22 13:27:06.013938 -------------------------------------------------------------------------------- Name : mujs Product : Fedora 25 Version : 0 Release : 8.20170124git4006739.fc25 URL : https://mujs.com/ Summary : An embeddable Javascript interpreter Description : MuJS is a lightweight Javascript interpreter designed for embedding in other software to extend them with scripting capabilities. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-10132, CVE-2016-10133, CVE-2016-10141, CVE-2017-5627, CVE-2017-5628. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1412967 - CVE-2016-10132 CVE-2016-10133 CVE-2016-10141 CVE-2017-5627 CVE-2017-5628 mujs: Multiple security issues https://bugzilla.redhat.com/show_bug.cgi?id=1412967 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mujs' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.