njs through 0.7.0, used in NGINX, was discovered to contain an out-of-bounds array access via njsvmcodetypeof in /src/njs_vmcode.c.
[
{
"source": "https://github.com/nginx/njs/commit/d457c9545e7e71ebb5c0479eb16b9d33175855e2",
"signature_type": "Function",
"id": "CVE-2021-46461-501009d4",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "njs_vmcode_typeof",
"file": "src/njs_vmcode.c"
},
"digest": {
"function_hash": "9392468354405660206887983019685688929",
"length": 792.0
}
},
{
"source": "https://github.com/nginx/njs/commit/d457c9545e7e71ebb5c0479eb16b9d33175855e2",
"signature_type": "Line",
"id": "CVE-2021-46461-f49df53d",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "src/test/njs_unit_test.c"
},
"digest": {
"line_hashes": [
"98564410132262592793995109969660261770",
"147510133104760375677726348496773441530",
"205029457978295310357353176216532695880"
],
"threshold": 0.9
}
}
]