cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c.
CVSS Details
- CVSS 3.1 Base Score: 7.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade cjson | Sep 2, 2024 | Apr 26, 2024 |
| Suse | — | Upgrade cJSON-develUpgrade libcjson1 | May 28, 2024 | Apr 26, 2024 |
| Ubuntu | — | Upgrade libcjson1 (Ubuntu Pro)Upgrade libcjson1 | May 28, 2024 | Apr 26, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub