CVE-2023-50471
published 2023-12-14CVE-2023-50471: cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.51%
71.5th percentile
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| davegamble | cjson | — | — |
| davegamble | cjson | >= 0 < 1.7.14-1+deb11u1 | 1.7.14-1+deb11u1 |
| davegamble | cjson | >= 0 < 1.7.15-1+deb12u1 | 1.7.15-1+deb12u1 |
| davegamble | cjson | >= 0 < 1.7.17-1 | 1.7.17-1 |
| davegamble | cjson | >= 0 < 1.7.17-1 | 1.7.17-1 |
| davegamble | cjson | >= 0 < 1.7.15-1ubuntu0.1~esm2 | 1.7.15-1ubuntu0.1~esm2 |
| davegamble | cjson | >= 0 < 1.7.17-1ubuntu0.1~esm2 | 1.7.17-1ubuntu0.1~esm2 |
| debian | cjson | < cjson 1.7.15-1+deb12u1 (bookworm) | cjson 1.7.15-1+deb12u1 (bookworm) |
| msrc | azl3_apparmor_3.1.7-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_ceph_18.2.2-8_on_azure_linux_3.0 | — | — |
| msrc | azl3_libglvnd_1.7.0-2_on_azure_linux_3.0 | — | — |
| msrc | cbl2_apparmor_3.0.4-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_pytorch_2.5.1-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
cjson vulnerabilities
osv·2024-05-23·CVSS 7.5
CVE-2023-50471 [HIGH] cjson vulnerabilities
cjson vulnerabilities
It was discovered that cJSON incorrectly handled certain input. An
attacker could possibly use this issue to cause cJSON to crash, resulting
in a denial of service. This issue only affected Ubuntu 22.04 LTS and
Ubuntu 23.10. (CVE-2023-50471, CVE-2023-50472)
Luo Jin discovered that cJSON incorrectly handled certain input. An
attacker could possibly use this issue to cause cJSON to crash, resulting
in a denial of service. (CVE-2024-31755)
OSV
CVE-2023-50471: cJSON v1
osv·2023-12-14·CVSS 7.5
CVE-2023-50471 [HIGH] CVE-2023-50471: cJSON v1
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
GHSA
GHSA-xgc4-4vwx-6v94: cJSON v1
ghsa_unreviewed·2023-12-14
CVE-2023-50471 [HIGH] CWE-476 GHSA-xgc4-4vwx-6v94: cJSON v1
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
Ubuntu
cJSON vulnerabilities
vendor_ubuntu·2024-05-23·CVSS 7.5
CVE-2023-50472 [HIGH] cJSON vulnerabilities
Title: cJSON vulnerabilities
Summary: cJSON could be made to crash if it received specially crafted
input.
It was discovered that cJSON incorrectly handled certain input. An
attacker could possibly use this issue to cause cJSON to crash, resulting
in a denial of service. This issue only affected Ubuntu 22.04 LTS and
Ubuntu 23.10. (CVE-2023-50471, CVE-2023-50472)
Luo Jin discovered that cJSON incorrectly handled certain input. An
attacker could possibly use this issue to cause cJSON to crash, resulting
in a denial of service. (CVE-2024-31755)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
cjson: segmentation violation in function cJSON_InsertItemInArray
vendor_redhat·2023-12-14·CVSS 7.5
CVE-2023-50471 [HIGH] CWE-476 cjson: segmentation violation in function cJSON_InsertItemInArray
cjson: segmentation violation in function cJSON_InsertItemInArray
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
A flaw was discovered in the cJSON package. Certain input conditions may trigger a null pointer dereference, which can lead to a denial of service.
Microsoft
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
vendor_msrc·2023-12-12·CVSS 7.5
CVE-2023-50471 [HIGH] CWE-476 cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Ye
Debian
CVE-2023-50471: cjson - cJSON v1.7.16 was discovered to contain a segmentation violation via the functio...
vendor_debian·2023·CVSS 7.5
CVE-2023-50471 [HIGH] CVE-2023-50471: cjson - cJSON v1.7.16 was discovered to contain a segmentation violation via the functio...
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
Scope: local
bookworm: resolved (fixed in 1.7.15-1+deb12u1)
bullseye: resolved (fixed in 1.7.14-1+deb11u1)
forky: resolved (fixed in 1.7.17-1)
sid: resolved (fixed in 1.7.17-1)
trixie: resolved (fixed in 1.7.17-1)
No detection rules found.
No public exploits indexed.
https://github.com/DaveGamble/cJSON/issues/802https://lists.debian.org/debian-lts-announce/2023/12/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EO4XCUTY3ZMVW4YBG6DBYVS5NSMNP6JY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JSI3LL6ZNKYNM5JKPA5FKZTATL4MPF7V/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YQOQ7CAOYBNHGAMNOR7ELGLC22HV3ZQV/https://github.com/DaveGamble/cJSON/issues/802https://lists.debian.org/debian-lts-announce/2023/12/msg00023.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EO4XCUTY3ZMVW4YBG6DBYVS5NSMNP6JY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JSI3LL6ZNKYNM5JKPA5FKZTATL4MPF7V/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YQOQ7CAOYBNHGAMNOR7ELGLC22HV3ZQV/https://lists.fedoraproject.org/archives/list/[email protected]/message/EO4XCUTY3ZMVW4YBG6DBYVS5NSMNP6JY/https://lists.fedoraproject.org/archives/list/[email protected]/message/JSI3LL6ZNKYNM5JKPA5FKZTATL4MPF7V/https://lists.fedoraproject.org/archives/list/[email protected]/message/YQOQ7CAOYBNHGAMNOR7ELGLC22HV3ZQV/
2023-12-14
Published