First published: Tue Dec 15 2020(Updated: )
jsonparser 1.0.0 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a GET call.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/buger/jsonparser | <1.1.1 | 1.1.1 |
jsonparser | =1.0.0 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35381 is considered a denial of service vulnerability.
To fix CVE-2020-35381, upgrade to jsonparser version 1.1.1 or later.
CVE-2020-35381 affects jsonparser versions prior to 1.1.1.
Yes, CVE-2020-35381 can impact Fedora versions 32 and 33 that use jsonparser 1.0.0.
CVE-2020-35381 enables attackers to cause a denial of service through specific GET calls.