First published: Thu Dec 14 2023(Updated: )
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/cjson | <1.7.15-1ubuntu0.1~ | 1.7.15-1ubuntu0.1~ |
ubuntu/cjson | <1.7.16-1ubuntu0.2 | 1.7.16-1ubuntu0.2 |
ubuntu/cjson | <1.7.17 | 1.7.17 |
debian/cjson | 1.7.14-1+deb11u1 1.7.15-1+deb12u1 1.7.18-3 | |
cJSON | =1.7.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50472 is classified as a high severity vulnerability due to its potential to cause segmentation violations in cJSON v1.7.16.
To fix CVE-2023-50472, upgrade cJSON to version 1.7.17 or later.
CVE-2023-50472 affects cJSON versions prior to 1.7.17, including version 1.7.16.
CVE-2023-50472 affects cJSON packages on Ubuntu and Debian systems that use vulnerable versions.
Yes, CVE-2023-50472 is publicly disclosed and details about it can be found in vulnerability databases.