Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-32292

Опубликовано: 22 авг. 2023
Источник: redhat
CVSS3: 0
EPSS Низкий

Описание

An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.

A flaw was found in the parseit() function in json_parse.c., a test app in the json-c library. The code error does not affect the library itself.

Отчет

Vulnerable code was introduced in json-c 0.15-20200726. Red Hat Enterprise Linux ships json-c-0.14-11 and prior, therefore, it is not-affected. This issue affects a test app and not the library itself, which lowers the impact of the flaw to none.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6json-cNot affected
Red Hat Enterprise Linux 7json-cNot affected
Red Hat Enterprise Linux 8json-cNot affected
Red Hat Enterprise Linux 9json-cNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-121->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2235514json-c: stack-buffer-overflow in parseit() in json_parse.c

EPSS

Процентиль: 33%
0.00133
Низкий

0 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.

CVSS3: 9.8
nvd
больше 2 лет назад

An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.

CVSS3: 9.8
msrc
больше 2 лет назад

An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.

CVSS3: 9.8
debian
больше 2 лет назад

An issue was discovered in json-c from 20200420 (post 0.14 unreleased ...

CVSS3: 9.8
github
больше 2 лет назад

An issue was discovered in json-c through 0.15-20200726. A stack-buffer-overflow exists in the function parseit located in json_parse.c. It allows an attacker to cause code Execution.

EPSS

Процентиль: 33%
0.00133
Низкий

0 Low

CVSS3