Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-1000217

Опубликовано: 20 авг. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corruption of data or even RCE. This attack appear to be exploitable via Depends on how application uses cJSON library. If application provides network interface then can be exploited over a network, otherwise just local.. This vulnerability appears to have been fixed in 1.7.4.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

1.7.5-1
esm-infra-legacy/trusty

DNE

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

1.7.4
xenial

DNE

Показывать по

EPSS

Процентиль: 61%
0.00418
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 7 лет назад

Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corruption of data or even RCE. This attack appear to be exploitable via Depends on how application uses cJSON library. If application provides network interface then can be exploited over a network, otherwise just local.. This vulnerability appears to have been fixed in 1.7.4.

CVSS3: 9.8
msrc
5 месяцев назад

Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability

CVSS3: 9.8
debian
больше 7 лет назад

Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use Af ...

CVSS3: 9.8
github
больше 3 лет назад

Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corruption of data or even RCE. This attack appear to be exploitable via Depends on how application uses cJSON library. If application provides network interface then can be exploited over a network, otherwise just local.. This vulnerability appears to have been fixed in 1.7.4.

EPSS

Процентиль: 61%
0.00418
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3