CVE-2023-48183

Name
CVE-2023-48183
Description
QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/bellard/quickjs/commit/c4cdd61a3ed284cd760faf6b00bbf0cb908da077
cve@mitre.org https://github.com/bellard/quickjs/issues/192

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:quickjs_project:quickjs:*:*:*:*:*:*:*:* quickjs >= None < 2023-12-09

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
quickjs edge-community 2021-03-27-r5 None possibly vulnerable
quickjs edge-community 0.20250913-r0 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
quickjs edge-community 0.20250426-r0 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
quickjs edge-community 0.20240113-r0 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
quickjs 3.23-community 0.20250426-r0 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
quickjs 3.22-community 2021-03-27-r5 None possibly vulnerable
quickjs 3.22-community 0.20250426-r0 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
quickjs 3.22-community 0.20240113-r0 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable