CVE-2023-50472: Null Pointer Dereference
Published Dec 14, 2023
·Updated
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSONSetValuestring at cJSON.c.
Affected Software
6 affected componentsFixes available
ubuntu/cjson<1.7.15-1ubuntu0.1~
1.7.15-1ubuntu0.1~
ubuntu/cjson<1.7.16-1ubuntu0.2
1.7.16-1ubuntu0.2
ubuntu/cjson<1.7.17
1.7.17
debian/cjson
1.7.14-1+deb11u11.7.15-1+deb12u11.7.18-3
Cjson Project Cjson=1.7.16
DaveGamble cJSON=1.7.16
Remediation
Patch Available
Event History
Dec 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 15, 2023
Data Sourced
via Red Hat·12:38 AM
DescriptionSeverityAffected Software
May 23, 2024
Data Sourced
via Launchpad·04:29 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-50472?
CVE-2023-50472 is classified as a high severity vulnerability due to its potential to cause segmentation violations in cJSON v1.7.16.
2
How do I fix CVE-2023-50472?
To fix CVE-2023-50472, upgrade cJSON to version 1.7.17 or later.
3
What versions of cJSON are affected by CVE-2023-50472?
CVE-2023-50472 affects cJSON versions prior to 1.7.17, including version 1.7.16.
4
Which operating systems are impacted by CVE-2023-50472?
CVE-2023-50472 affects cJSON packages on Ubuntu and Debian systems that use vulnerable versions.
5
Is CVE-2023-50472 publicly known?
Yes, CVE-2023-50472 is publicly disclosed and details about it can be found in vulnerability databases.