First published: Fri Jul 19 2019(Updated: )
DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSON_GetObjectItemCaseSensitive() function. The attack vector is: crafted json file. The fixed version is: 1.7.9 and later.
Credit: josh@bress.net
Affected Software | Affected Version | How to fix |
---|---|---|
Cjson Project Cjson | =1.7.8 | |
Oracle TimesTen In-Memory Database | <18.1.3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1010239 is a vulnerability in the cJSON library version 1.7.8 that allows for a null dereference leading to denial of service.
CVE-2019-1010239 can cause a denial of service as it results in a null dereference.
The cJSON_GetObjectItemCaseSensitive() function is affected by CVE-2019-1010239.
The attack vector for CVE-2019-1010239 is a crafted JSON file.
To fix the vulnerability, update to cJSON version 1.7.9 or higher.