CVE-2019-1010239: Null Pointer Dereference
Published Jul 19, 2019
·Updated
DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSONGetObjectItemCaseSensitive() function. The attack vector is: crafted json file. The fixed version is: 1.7.9 and later.
Affected Software
3 affected components
Cjson Project Cjson=1.7.8
Oracle TimesTen In-Memory Database<18.1.3.1.0
DaveGamble cJSON=1.7.8
Remediation
Patch Available
Event History
Jul 19, 2019
CVE Published
via MITRE·04:41 PM
Data Sourced
via MITRE·04:41 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-1010239?
CVE-2019-1010239 is a vulnerability in the cJSON library version 1.7.8 that allows for a null dereference leading to denial of service.
2
How does CVE-2019-1010239 impact the software?
CVE-2019-1010239 can cause a denial of service as it results in a null dereference.
3
Which component of cJSON is affected by CVE-2019-1010239?
The cJSON_GetObjectItemCaseSensitive() function is affected by CVE-2019-1010239.
4
What is the attack vector for CVE-2019-1010239?
The attack vector for CVE-2019-1010239 is a crafted JSON file.
5
How can I fix the vulnerability?
To fix the vulnerability, update to cJSON version 1.7.9 or higher.