REDHAT-BUG-2392894: High severity cJSON cJSON vulnerability
cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decodearrayindexfrompointer function in cJSONUtils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2392894?
The severity of REDHAT-BUG-2392894 is critical due to the potential for out-of-bounds access and data exposure.
How do I fix REDHAT-BUG-2392894?
To fix REDHAT-BUG-2392894, upgrade your cJSON library to version 1.7.19 or later.
What type of vulnerability is REDHAT-BUG-2392894?
REDHAT-BUG-2392894 is an out-of-bounds access vulnerability that affects cJSON versions 1.5.0 through 1.7.18.
Who is affected by REDHAT-BUG-2392894?
Developers and users of the cJSON library versions 1.5.0 to 1.7.18 are affected by REDHAT-BUG-2392894.
Can REDHAT-BUG-2392894 be exploited remotely?
Yes, REDHAT-BUG-2392894 can be exploited remotely by attackers using specially crafted JSON pointer strings.