njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is in place.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-06-29T23:29:57

Updated: 2024-08-04T23:41:10.063Z

Reserved: 2019-06-29T00:00:00

Link: CVE-2019-13067

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-06-30T00:15:11.283

Modified: 2024-11-21T04:24:07.910

Link: CVE-2019-13067

cve-icon Redhat

No data.