CVE-2021-45958
published 2022-01-01CVE-2021-45958: UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use…
PriorityP426medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.55%
72.3th percentile
UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | ujson | < ujson 5.2.0-1 (bookworm) | ujson 5.2.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| ultrajson_project | ultrajson | < 5.2.0 | 5.2.0 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
UltraJSON vulnerabilities
vendor_ubuntu·2024-02-14·CVSS 5.5
CVE-2022-31117 [MEDIUM] UltraJSON vulnerabilities
Title: UltraJSON vulnerabilities
Summary: Several security issues were fixed in UltraJSON.
It was discovered that UltraJSON incorrectly handled certain input with
a large amount of indentation. An attacker could possibly use this issue
to crash the program, resulting in a denial of service. (CVE-2021-45958)
Jake Miller discovered that UltraJSON incorrectly decoded certain
characters. An attacker could possibly use this issue to cause key
confusion and overwrite values in dictionaries. (CVE-2022-31116)
It was discovered that UltraJSON incorrectly handled an error when
reallocating a buffer for string decoding. An attacker could possibly
use this issue to corrupt memory. (CVE-2022-31117)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
UltraJSON vulnerability
vendor_ubuntu·2024-02-14·CVSS 5.5
CVE-2021-45958 [MEDIUM] UltraJSON vulnerability
Title: UltraJSON vulnerability
Summary: UltraJSON could be made to crash if it received specially crafted
input.
USN-6629-1 fixed vulnerabilities in UltraJSON.
This update provides the corresponding updates for Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that UltraJSON incorrectly handled certain input with
a large amount of indentation. An attacker could possibly use this issue
to crash the program, resulting in a denial of service. (CVE-2021-45958)
Jake Miller discovered that UltraJSON incorrectly decoded certain
characters. An attacker could possibly use this issue to cause key
confusion and overwrite values in dictionaries. (CVE-2022-31116)
It was discovered that UltraJSON incorrectly handled an error when
reallocating a buffer for string decoding. An attacker
Ubuntu
UltraJSON vulnerabilities
vendor_ubuntu·2024-02-14·CVSS 5.5
CVE-2022-31117 [MEDIUM] UltraJSON vulnerabilities
Title: UltraJSON vulnerabilities
Summary: Several security issues were fixed in UltraJSON.
USN-6629-1 fixed vulnerabilities in UltraJSON.
This update provides the corresponding updates for Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that UltraJSON incorrectly handled certain input with
a large amount of indentation. An attacker could possibly use this issue
to crash the program, resulting in a denial of service. (CVE-2021-45958)
Jake Miller discovered that UltraJSON incorrectly decoded certain
characters. An attacker could possibly use this issue to cause key
confusion and overwrite values in dictionaries. (CVE-2022-31116)
It was discovered that UltraJSON incorrectly handled an error when
reallocating a buffer for string decoding. An attacker could possibly
use thi
Debian
CVE-2021-45958: ujson - UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_...
vendor_debian·2021·CVSS 5.5
CVE-2021-45958 [MEDIUM] CVE-2021-45958: ujson - UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_...
UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.
Scope: local
bookworm: resolved (fixed in 5.2.0-1)
bullseye: open
forky: resolved (fixed in 5.2.0-1)
sid: resolved (fixed in 5.2.0-1)
trixie: resolved (fixed in 5.2.0-1)
OSV
ujson vulnerability
osv·2024-02-14·CVSS 5.5
CVE-2021-45958 [MEDIUM] ujson vulnerability
ujson vulnerability
USN-6629-1 fixed vulnerabilities in UltraJSON.
This update provides the corresponding updates for Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that UltraJSON incorrectly handled certain input with
a large amount of indentation. An attacker could possibly use this issue
to crash the program, resulting in a denial of service. (CVE-2021-45958)
Jake Miller discovered that UltraJSON incorrectly decoded certain
characters. An attacker could possibly use this issue to cause key
confusion and overwrite values in dictionaries. (CVE-2022-31116)
It was discovered that UltraJSON incorrectly handled an error when
reallocating a buffer for string decoding. An attacker could possibly
use this issue to corrupt memory. (CVE-2022-31117)
OSV
ujson vulnerabilities
osv·2024-02-14·CVSS 5.5
CVE-2021-45958 [MEDIUM] ujson vulnerabilities
ujson vulnerabilities
It was discovered that UltraJSON incorrectly handled certain input with
a large amount of indentation. An attacker could possibly use this issue
to crash the program, resulting in a denial of service. (CVE-2021-45958)
Jake Miller discovered that UltraJSON incorrectly decoded certain
characters. An attacker could possibly use this issue to cause key
confusion and overwrite values in dictionaries. (CVE-2022-31116)
It was discovered that UltraJSON incorrectly handled an error when
reallocating a buffer for string decoding. An attacker could possibly
use this issue to corrupt memory. (CVE-2022-31117)
OSV
ujson vulnerabilities
osv·2024-02-14·CVSS 5.5
CVE-2021-45958 [MEDIUM] ujson vulnerabilities
ujson vulnerabilities
USN-6629-1 fixed vulnerabilities in UltraJSON.
This update provides the corresponding updates for Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that UltraJSON incorrectly handled certain input with
a large amount of indentation. An attacker could possibly use this issue
to crash the program, resulting in a denial of service. (CVE-2021-45958)
Jake Miller discovered that UltraJSON incorrectly decoded certain
characters. An attacker could possibly use this issue to cause key
confusion and overwrite values in dictionaries. (CVE-2022-31116)
It was discovered that UltraJSON incorrectly handled an error when
reallocating a buffer for string decoding. An attacker could possibly
use this issue to corrupt memory. (CVE-2022-31117)
GHSA
UltraJSON vulnerable to Out-of-bounds Write
ghsa·2022-01-21
CVE-2021-45958 [MEDIUM] CWE-787 UltraJSON vulnerable to Out-of-bounds Write
UltraJSON vulnerable to Out-of-bounds Write
UltraJSON (aka ujson) 1.34 through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode).
OSV
UltraJSON vulnerable to Out-of-bounds Write
osv·2022-01-21
CVE-2021-45958 [MEDIUM] UltraJSON vulnerable to Out-of-bounds Write
UltraJSON vulnerable to Out-of-bounds Write
UltraJSON (aka ujson) 1.34 through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode).
OSV
CVE-2021-45958: UltraJSON (aka ujson) through 5
osv·2022-01-01·CVSS 5.5
CVE-2021-45958 [MEDIUM] CVE-2021-45958: UltraJSON (aka ujson) through 5
UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=36009https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ujson/OSV-2021-955.yamlhttps://github.com/ultrajson/ultrajson/issues/501https://github.com/ultrajson/ultrajson/issues/502#issuecomment-1031747284https://github.com/ultrajson/ultrajson/pull/504https://lists.debian.org/debian-lts-announce/2022/02/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CN7W3GOXALINKFUUE7ICQIC2EF5HNKUQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NAU5N4A7EUK2AMUCOLYDD5ARXAJYZBD2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O6JUWQTJLA2CMG4CJN7DCUVSOXLZIIXL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ULX35TSWLBBIMEH44MUORPXYYRZKEDC6/https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=36009https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ujson/OSV-2021-955.yamlhttps://github.com/ultrajson/ultrajson/issues/501https://github.com/ultrajson/ultrajson/issues/502#issuecomment-1031747284https://github.com/ultrajson/ultrajson/pull/504https://lists.debian.org/debian-lts-announce/2022/02/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CN7W3GOXALINKFUUE7ICQIC2EF5HNKUQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NAU5N4A7EUK2AMUCOLYDD5ARXAJYZBD2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O6JUWQTJLA2CMG4CJN7DCUVSOXLZIIXL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ULX35TSWLBBIMEH44MUORPXYYRZKEDC6/
2022-01-01
Published