Описание
parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.
A heap based buffer overflow flaw was found in cjson when calling the cJSON_ParseWithLength function. Specially crafted input may lead to arbitrary memory corruption.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Satellite 6 | cjson | Fix deferred | ||
| Red Hat Satellite 6 | satellite-capsule:el8/cjson | Fix deferred | ||
| Red Hat Satellite 6 | satellite:el8/cjson | Fix deferred |
Показывать по
Дополнительная информация
Статус:
5.1 Medium
CVSS3
Связанные уязвимости
parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.
parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.
parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.
parse_string in cJSON before 1.7.18 has a heap-based buffer over-read ...
parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.
5.1 Medium
CVSS3