First published: Mon Sep 26 2016(Updated: )
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Iperf3 Project Iperf3 | >=3.0<3.0.12 | |
Iperf3 Project Iperf3 | >=3.1<3.1.3 | |
Novell Suse Package Hub For Suse Linux Enterprise | =12 | |
openSUSE Leap | =42.1 | |
openSUSE openSUSE | =13.2 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.