First published: Mon Aug 20 2018(Updated: )
Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker must be able to force victim to print JSON data, depending on how cJSON library is used this could be either local or over a network. This vulnerability appears to have been fixed in 1.7.3.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cjson Project Cjson | <1.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-1000216.
The severity of CVE-2018-1000216 is high with a severity value of 8.8.
The affected software for CVE-2018-1000216 is cJSON version 1.7.2 and earlier.
The CWE ID for CVE-2018-1000216 is CWE-415.
CVE-2018-1000216 can be exploited by forcing the victim to print JSON data, depending on how the cJSON library is used.