CVE-2018-1000217: Use After Free
Published Aug 20, 2018
·Updated
Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability
Affected Software
3 affected componentsFixes available
Event History
Aug 20, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:29 PM
DescriptionSeverityWeaknessAffected Software
Sep 3, 2025
Data Sourced
via Microsoft·07:47 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:47 PM
Affected Software
Updated
via Microsoft·07:47 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2018-1000217?
CVE-2018-1000217 is a vulnerability in the cJSON library, specifically version 1.7.3 and earlier, that allows for a use after free attack.
2
What is the severity of CVE-2018-1000217?
CVE-2018-1000217 has a severity level of 9.8, which is classified as critical.
3
How does CVE-2018-1000217 affect software?
CVE-2018-1000217 affects software that uses the cJSON library, specifically version 1.7.3 and earlier.
4
What risks are associated with CVE-2018-1000217?
CVE-2018-1000217 can lead to a crash, data corruption, or even remote code execution.
5
How can I fix CVE-2018-1000217?
To fix CVE-2018-1000217, it is recommended to update to version 1.7.4 or later of the cJSON library.