First published: Mon Jan 27 2025(Updated: )
A NULL Pointer Dereference vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON as input.
Credit: prodsec@nozominetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cesanta Frozen | <1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0696 is a vulnerability that can cause crashes in applications using Cesanta Frozen versions less than 1.7.
To fix CVE-2025-0696, update the Cesanta Frozen library to version 1.7 or later.
CVE-2025-0696 is caused by a NULL Pointer Dereference when handling maliciously crafted JSON input.
CVE-2025-0696 affects any system embedding Cesanta Frozen versions prior to 1.7.
Yes, CVE-2025-0696 can be exploited remotely by supplying crafted JSON to the vulnerable software.