An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade json-c | Mar 21, 2024 | Aug 22, 2023 |
| Debian | — | Upgrade json-c | Sep 5, 2023 | Aug 22, 2023 |
| Gentoo Linux | — | Upgrade dev-libs/json-c. | Aug 8, 2024 | Aug 22, 2023 |
| Huawei Euleros 2_0_sp10 | — | Upgrade json-c | Jan 10, 2024 | Aug 22, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade json-c | Jan 10, 2024 | Aug 22, 2023 |
| Ubuntu | — | Upgrade libjson-c5 | Aug 29, 2023 | Aug 22, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 22, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub