First published: Fri Feb 03 2023(Updated: )
Buffer OverFlow Vulnerability in Barenboim json-parser master and v1.1.0 fixed in v1.1.1 allows an attacker to execute arbitrary code via the json_value_parse function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
jsonparser | =1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-23088.
The title of the vulnerability is Buffer OverFlow Vulnerability in Barenboim json-parser master and v1.1.0 fixed in v1.1.1.
The description of the vulnerability is that it allows an attacker to execute arbitrary code via the json_value_parse function.
The severity of the vulnerability is critical with a CVSS score of 9.8.
The software version affected by the vulnerability is json-parser 1.1.0.
The vulnerability can be fixed by updating to version 1.1.1 of json-parser.
Yes, the reference for this vulnerability is https://github.com/Barenboim/json-parser/issues/7.
The Common Weakness Enumeration (CWE) ID associated with the vulnerability is CWE-119 and CWE-787.