cbcvebase.
CVE-2020-12762
published 2020-05-09

CVE-2020-12762: json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianjson-c< json-c 0.13.1+dfsg-8 (bookworm)json-c 0.13.1+dfsg-8 (bookworm)
debianlibfastjson< json-c 0.13.1+dfsg-8 (bookworm)json-c 0.13.1+dfsg-8 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
json-cjson-c< 0.15-202007260.15-20200726
json-cjson-c>= 0 < 0.13.1+dfsg-80.13.1+dfsg-8
json-cjson-c>= 0 < 0.13.1+dfsg-80.13.1+dfsg-8
json-cjson-c>= 0 < 0.13.1+dfsg-80.13.1+dfsg-8
json-cjson-c>= 0 < 0.13.1+dfsg-80.13.1+dfsg-8
json-cjson-c>= 0 < 0.11-4ubuntu2.60.11-4ubuntu2.6
json-cjson-c>= 0 < 0.12.1-1.3ubuntu0.30.12.1-1.3ubuntu0.3
json-cjson-c>= 0 < 0.13.1+dfsg-7ubuntu0.30.13.1+dfsg-7ubuntu0.3
json-cjson-c>= 0 < 0.11-3ubuntu1.2+esm30.11-3ubuntu1.2+esm3
msrccbl2_json-c_0.15-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH