CVE-2019-11835: Critical severity lua cjson vulnerability
Published May 9, 2019
·Updated
cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.
Affected Software
3 affected components
Cjson Project Cjson<1.7.11
Oracle TimesTen In-Memory Database<18.1.3.1.0
DaveGamble cJSON<1.7.11
Remediation
Patch Available
Event History
May 9, 2019
CVE Published
via MITRE·04:38 AM
Data Sourced
via MITRE·04:38 AM
Description
Data Sourced
via NVD·05:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-11835?
CVE-2019-11835 is a vulnerability in cJSON before version 1.7.11 that allows out-of-bounds access related to multiline comments.
2
How severe is CVE-2019-11835?
CVE-2019-11835 is considered critical with a severity score of 9.8.
3
Which software is affected by CVE-2019-11835?
The vulnerability affects cJSON versions prior to 1.7.11 and Oracle TimesTen In-Memory Database versions up to 18.1.3.1.0.
4
How can I fix CVE-2019-11835?
To fix CVE-2019-11835, update cJSON to version 1.7.11 or apply the necessary patches provided by the vendor for Oracle TimesTen In-Memory Database.
5
Where can I find more information about CVE-2019-11835?
More information about CVE-2019-11835 can be found on the GitHub page of cJSON, including the issue reports and the release tag for version 1.7.11.