First published: Thu May 09 2019(Updated: )
cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
cJSON | <1.7.11 | |
Oracle TimesTen In-Memory Database | <18.1.3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11834 is a vulnerability that allows out-of-bounds access in cJSON before version 1.7.11, related to \x00 in a string literal.
The severity of CVE-2019-11834 is critical with a CVSS score of 9.8.
cJSON before version 1.7.11 and Oracle TimesTen In-Memory Database up to version 18.1.3.1.0 are affected by CVE-2019-11834.
To fix CVE-2019-11834, update cJSON to version 1.7.11 or later.
The CWEs associated with CVE-2019-11834 are CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write).