UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. In versions prior to 5.4.0 an error occurring while reallocating a buffer for string decoding can cause the buffer to get freed twice. Due to how UltraJSON uses the internal decoder, this double free is impossible to trigger from Python. This issue has been resolved in version 5.4.0 and all users should upgrade to UltraJSON 5.4.0. There are no known workarounds for this issue.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-ujson | Aug 22, 2024 | Jul 5, 2022 |
| Centos_linux | — | Upgrade python3-ujsonUpgrade python3-ujson-debuginfoUpgrade python-ujson-debugsource | Dec 9, 2022 | Jul 5, 2022 |
| Debian | — | Upgrade ujson | Jul 30, 2024 | Jul 5, 2022 |
| Gentoo Linux | — | Upgrade dev-python/ujson. | Mar 4, 2024 | Jul 5, 2022 |
| Redhat_linux | — | Upgrade python3-ujson-debuginfoUpgrade python-ujson-debugsourceUpgrade python3-ujson | Dec 9, 2022 | Jul 5, 2022 |
| Suse | — | Upgrade python3-ujsonUpgrade python2-ujson | Oct 26, 2022 | Jul 5, 2022 |
| Ubuntu | — | Upgrade python-ujson (Ubuntu Pro)Upgrade python3-ujson (Ubuntu Pro) | Feb 14, 2024 | Jul 5, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub