cbcvebase.
CVE-2020-12762
published 2020-05-09

CVE-2020-12762: json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.89%
77.4th percentile
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianjson-c< json-c 0.13.1+dfsg-8 (bookworm)json-c 0.13.1+dfsg-8 (bookworm)
debianlibfastjson< json-c 0.13.1+dfsg-8 (bookworm)json-c 0.13.1+dfsg-8 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
json-cjson-c< 0.15-202007260.15-20200726
json-cjson-c>= 0 < 0.13.1+dfsg-80.13.1+dfsg-8
json-cjson-c>= 0 < 0.13.1+dfsg-80.13.1+dfsg-8
json-cjson-c>= 0 < 0.13.1+dfsg-80.13.1+dfsg-8
json-cjson-c>= 0 < 0.13.1+dfsg-80.13.1+dfsg-8
json-cjson-c>= 0 < 0.11-4ubuntu2.60.11-4ubuntu2.6
json-cjson-c>= 0 < 0.12.1-1.3ubuntu0.30.12.1-1.3ubuntu0.3
json-cjson-c>= 0 < 0.13.1+dfsg-7ubuntu0.30.13.1+dfsg-7ubuntu0.3
json-cjson-c>= 0 < 0.11-3ubuntu1.2+esm30.11-3ubuntu1.2+esm3
msrccbl2_json-c_0.15-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.