Search CVE reports
1 – 10 of 16 results
Some fixes available 4 of 5
cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON...
1 affected package
cjson
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| cjson | Fixed | Fixed | Fixed | — |
parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.
1 affected package
cjson
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| cjson | Fixed | Fixed | Fixed | — |
Some fixes available 3 of 5
cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.
1 affected package
cjson
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| cjson | Fixed | Fixed | Fixed | — |
cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c.
1 affected package
cjson
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| cjson | Fixed | Fixed | Not affected | — |
Some fixes available 2 of 3
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.
1 affected package
cjson
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| cjson | Not affected | Fixed | Not affected | Ignored |
Some fixes available 2 of 3
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
1 affected package
cjson
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| cjson | Not affected | Fixed | Not affected | Ignored |
Some fixes available 5 of 14
Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corruption and potentially remote code execution. The...
3 affected packages
redis, lua-cjson, lua-cmsgpack
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| redis | Not affected | Fixed | Fixed | Fixed |
| lua-cjson | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| lua-cmsgpack | Not in release | Not in release | — | — |
DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSON_GetObjectItemCaseSensitive()...
1 affected package
cjson
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| cjson | — | — | — | Not in release |
cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.
1 affected package
cjson
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| cjson | — | — | — | Not in release |
cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
1 affected package
cjson
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| cjson | — | — | — | Not in release |