CVE-2023-50471: Null Pointer Dereference
Published Dec 14, 2023
·Updated
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSONInsertItemInArray at cJSON.c.
Affected Software
3 affected componentsFixes available
debian/cjson
1.7.14-1+deb11u11.7.15-1+deb12u11.7.18-3
Cjson Project Cjson=1.7.16
DaveGamble cJSON=1.7.16
Remediation
Patch Available
Event History
Dec 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 15, 2023
Data Sourced
via Red Hat·12:28 AM
DescriptionSeverityAffected Software
May 23, 2024
Data Sourced
via Launchpad·04:29 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·04:47 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-50471?
CVE-2023-50471 has not been assigned a CVSS score, but it is categorized as a segmentation violation which can lead to application crashes.
2
How do I fix CVE-2023-50471?
To fix CVE-2023-50471, update cJSON to a version later than 1.7.16, such as 1.7.18.
3
What versions of cJSON are affected by CVE-2023-50471?
cJSON version 1.7.16 is the affected version in CVE-2023-50471.
4
What is the impact of CVE-2023-50471?
CVE-2023-50471 can lead to a segmentation fault, causing instability in applications using cJSON version 1.7.16.
5
Is CVE-2023-50471 present in Debian packages?
Yes, CVE-2023-50471 affects the cJSON package version 1.7.16 in Debian.