Candidate: CVE-2020-23323 PublicDate: 2021-06-10 23:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-23323 https://github.com/jerryscript-project/jerryscript/issues/3871 Description: There is a heap-buffer-overflow at re-parser.c in re_parse_char_escape in JerryScript 2.2.0. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=989991 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_iotjs: upstream: https://github.com/jerryscript-project/jerryscript/pull/3875 upstream_iotjs: released (2.3.0) trusty_iotjs: ignored (out of standard support) trusty/esm_iotjs: DNE xenial_iotjs: ignored (out of standard support) bionic_iotjs: needed focal_iotjs: DNE groovy_iotjs: ignored (reached end-of-life) hirsute_iotjs: ignored (reached end-of-life) impish_iotjs: needed jammy_iotjs: needed devel_iotjs: needed