A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.
| Software | From | Fixed in |
|---|---|---|
| artifex / mujs | 1.0.0 | 1.3.2 |
| debian / debian_linux | 11.0 | 11.0.x |
| fedoraproject / fedora | 37 | 37.x |