CVE-2013-6371
published 2014-04-22CVE-2013-6371: The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.26%
87.0th percentile
The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | json-c | < json-c 0.11-4 (bookworm) | json-c 0.11-4 (bookworm) |
| fedoraproject | fedora | — | — |
| json-c | json-c | < 0.12-20140410 | 0.12-20140410 |
| json-c | json-c | >= 0 < 0.11-4 | 0.11-4 |
| json-c | json-c | >= 0 < 0.11-4 | 0.11-4 |
| json-c | json-c | >= 0 < 0.11-4 | 0.11-4 |
| json-c | json-c | >= 0 < 0.11-4 | 0.11-4 |
| json-c | json-c | >= 0 < 0.11-3ubuntu1.2 | 0.11-3ubuntu1.2 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qmhf-38fc-rg36: The hash functionality in json-c before 0
ghsa_unreviewed·2022-05-17
CVE-2013-6371 [MEDIUM] GHSA-qmhf-38fc-rg36: The hash functionality in json-c before 0
The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions.
OSV
json-c vulnerabilities
osv·2014-06-12·CVSS 5.0
CVE-2013-6370 [MEDIUM] json-c vulnerabilities
json-c vulnerabilities
Florian Weimer discovered that json-c incorrectly handled buffer lengths.
An attacker could use this issue with a specially-crafted large JSON
document to cause json-c to crash, resulting in a denial of service.
(CVE-2013-6370)
Florian Weimer discovered that json-c incorrectly handled hash arrays. An
attacker could use this issue with a specially-crafted JSON document to
cause json-c to consume CPU resources, resulting in a denial of service.
(CVE-2013-6371)
OSV
CVE-2013-6371: The hash functionality in json-c before 0
osv·2014-04-22·CVSS 5.0
CVE-2013-6371 [MEDIUM] CVE-2013-6371: The hash functionality in json-c before 0
The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions.
Ubuntu
json-c vulnerabilities
vendor_ubuntu·2014-06-12·CVSS 5.0
CVE-2013-6370 [MEDIUM] json-c vulnerabilities
Title: json-c vulnerabilities
Summary: json-c could be made to crash or consume CPU if it processed a specially
crafted JSON document.
Florian Weimer discovered that json-c incorrectly handled buffer lengths.
An attacker could use this issue with a specially-crafted large JSON
document to cause json-c to crash, resulting in a denial of service.
(CVE-2013-6370)
Florian Weimer discovered that json-c incorrectly handled hash arrays. An
attacker could use this issue with a specially-crafted JSON document to
cause json-c to consume CPU resources, resulting in a denial of service.
(CVE-2013-6371)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
json-c: hash collision DoS
vendor_redhat·2014-04-09·CVSS 5.0
CVE-2013-6371 [MEDIUM] json-c: hash collision DoS
json-c: hash collision DoS
The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions.
Package: php55-php-pecl-jsonc (Red Hat Software Collections) - Affected
Debian
CVE-2013-6371: json-c - The hash functionality in json-c before 0.12 allows context-dependent attackers ...
vendor_debian·2013·CVSS 5.0
CVE-2013-6371 [MEDIUM] CVE-2013-6371: json-c - The hash functionality in json-c before 0.12 allows context-dependent attackers ...
The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions.
Scope: local
bookworm: resolved (fixed in 0.11-4)
bullseye: resolved (fixed in 0.11-4)
forky: resolved (fixed in 0.11-4)
sid: resolved (fixed in 0.11-4)
trixie: resolved (fixed in 0.11-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6371 CVE-2013-6370 json-c: various flaws [epel-all]
bugzilla·2014-04-09·CVSS 5.0
CVE-2013-6371 [MEDIUM] CVE-2013-6371 CVE-2013-6370 json-c: various flaws [epel-all]
CVE-2013-6371 CVE-2013-6370 json-c: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multipl
Bugzilla
CVE-2013-6371 CVE-2013-6370 json-c: various flaws [fedora-all]
bugzilla·2014-04-09·CVSS 5.0
CVE-2013-6371 [MEDIUM] CVE-2013-6371 CVE-2013-6370 json-c: various flaws [fedora-all]
CVE-2013-6371 CVE-2013-6370 json-c: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple s
Bugzilla
CVE-2013-6371 json-c: hash collision DoS
bugzilla·2013-11-20·CVSS 5.0
CVE-2013-6371 [MEDIUM] CVE-2013-6371 json-c: hash collision DoS
CVE-2013-6371 json-c: hash collision DoS
Florian Weimer reported that the hash function in the json-c library was weak, and that parsing smallish JSON strings showed quadratic timing behaviour. This could cause an application linked to the json-c library, and that processes some specially-crafted JSON data, to use excessive amounts of CPU.
Acknowledgements:
This issue was discovered by Florian Weimer of the Red Hat Product Security Team.
Discussion:
Public via:
https://github.com/json-c/json-c/commit/64e36901a0614bf64a19bc3396469c66dcd0b015
---
Created json-c tracking bugs for this issue:
Affects: fedora-all [bug 1085676]
Affects: epel-all [bug 1085677]
---
json-c-0.11-6.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it i
http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131845.htmlhttp://secunia.com/advisories/57791http://www.mandriva.com/security/advisories?name=MDVSA-2014:079http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/66715https://bugzilla.redhat.com/show_bug.cgi?id=1032311https://exchange.xforce.ibmcloud.com/vulnerabilities/92541https://github.com/json-c/json-c/commit/64e36901a0614bf64a19bc3396469c66dcd0b015http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131845.htmlhttp://secunia.com/advisories/57791http://www.mandriva.com/security/advisories?name=MDVSA-2014:079http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/66715https://bugzilla.redhat.com/show_bug.cgi?id=1032311https://exchange.xforce.ibmcloud.com/vulnerabilities/92541https://github.com/json-c/json-c/commit/64e36901a0614bf64a19bc3396469c66dcd0b015
2014-04-22
Published