Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-53154

Опубликовано: 23 мая 2025
Источник: redhat
CVSS3: 5.1
EPSS Низкий

Описание

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

A heap based buffer overflow flaw was found in cjson when calling the cJSON_ParseWithLength function. Specially crafted input may lead to arbitrary memory corruption.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6cjsonFix deferred
Red Hat Satellite 6satellite-capsule:el8/cjsonFix deferred
Red Hat Satellite 6satellite:el8/cjsonFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2368279cjson: Heap based buffer overflow at cJSON_ParseWithLength function

EPSS

Процентиль: 8%
0.00029
Низкий

5.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 2.9
ubuntu
9 месяцев назад

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

CVSS3: 2.9
nvd
9 месяцев назад

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

CVSS3: 2.9
msrc
5 месяцев назад

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

CVSS3: 2.9
debian
9 месяцев назад

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read ...

CVSS3: 2.9
github
9 месяцев назад

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

EPSS

Процентиль: 8%
0.00029
Низкий

5.1 Medium

CVSS3