CVE-2019-11834: Critical severity lua cjson vulnerability
Published May 9, 2019
·Updated
cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
Affected Software
3 affected components
Cjson Project Cjson<1.7.11
Oracle TimesTen In-Memory Database<18.1.3.1.0
DaveGamble cJSON<1.7.11
Remediation
Patch Available
Event History
May 9, 2019
CVE Published
via MITRE·04:38 AM
Data Sourced
via MITRE·04:38 AM
Description
Data Sourced
via NVD·05:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-11834?
CVE-2019-11834 is a vulnerability that allows out-of-bounds access in cJSON before version 1.7.11, related to \x00 in a string literal.
2
What is the severity of CVE-2019-11834?
The severity of CVE-2019-11834 is critical with a CVSS score of 9.8.
3
Which software is affected by CVE-2019-11834?
cJSON before version 1.7.11 and Oracle TimesTen In-Memory Database up to version 18.1.3.1.0 are affected by CVE-2019-11834.
4
How do I fix CVE-2019-11834?
To fix CVE-2019-11834, update cJSON to version 1.7.11 or later.
5
What are the Common Weakness Enumerations (CWEs) associated with CVE-2019-11834?
The CWEs associated with CVE-2019-11834 are CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write).