Opened 6 months ago

Closed 6 months ago

#18767 closed enhancement (fixed)

SpiderMonkey-115.4.0

Reported by: ken@… Owned by: ken@…
Priority: elevated Milestone: 12.1
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

The changes in js/src since 115.3.1 appear to be for weak reference handling, with an added test referencing bug 1852729. That bug is not open for public access, so I assume it is a vulnerability fix.

Change History (4)

comment:1 by ken@…, 6 months ago

Owner: changed from blfs-book to ken@…
Priority: normalelevated
Status: newassigned

That is in the release notes for 119.0, probably also 115.4.0 but I have not looked at that yet.

CVE-2023-5728: Improper object tracking during GC in the JavaScript engine could have led to a crash. Rated as "moderate" i.e. medium.

comment:2 by ken@…, 6 months ago

On reflection, crashing this should be regarded as High.

comment:4 by ken@…, 6 months ago

Resolution: fixed
Status: assignedclosed

SA 12.0-030

Note: See TracTickets for help on using tickets.