Debian Json-C vulnerabilities

4 known vulnerabilities affecting debian/json-c.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2021-32292CRITICALCVSS 9.8fixed in json-c 0.16-1 (bookworm)2021
CVE-2021-32292 [CRITICAL] CVE-2021-32292: json-c - An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) thro... An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit. Scope: local bookworm: resolved (fixed in 0.16-1) bullseye: resolved (fixed in 0.15-2+deb11u1) forky: resolved (fixed in 0.16-1) sid: resolved (fixed
debian
CVE-2020-12762HIGHCVSS 7.8fixed in json-c 0.13.1+dfsg-8 (bookworm)2020
CVE-2020-12762 [HIGH] CVE-2020-12762: json-c - json-c through 0.14 has an integer overflow and out-of-bounds write via a large ... json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. Scope: local bookworm: resolved (fixed in 0.13.1+dfsg-8) bullseye: resolved (fixed in 0.13.1+dfsg-8) forky: resolved (fixed in 0.13.1+dfsg-8) sid: resolved (fixed in 0.13.1+dfsg-8) trixie: resolved (fixed in 0.13.1+dfsg-8)
debian
CVE-2013-6371MEDIUMCVSS 5.0fixed in json-c 0.11-4 (bookworm)2013
CVE-2013-6371 [MEDIUM] CVE-2013-6371: json-c - The hash functionality in json-c before 0.12 allows context-dependent attackers ... The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions. Scope: local bookworm: resolved (fixed in 0.11-4) bullseye: resolved (fixed in 0.11-4) forky: resolved (fixed in 0.11-4) sid: resolved (fixed in 0.11-4) trixie: resolved (fixed in 0.11-4)
debian
CVE-2013-6370MEDIUMCVSS 5.0fixed in json-c 0.11-4 (bookworm)2013
CVE-2013-6370 [MEDIUM] CVE-2013-6370: json-c - Buffer overflow in the printbuf APIs in json-c before 0.12 allows remote attacke... Buffer overflow in the printbuf APIs in json-c before 0.12 allows remote attackers to cause a denial of service via unspecified vectors. Scope: local bookworm: resolved (fixed in 0.11-4) bullseye: resolved (fixed in 0.11-4) forky: resolved (fixed in 0.11-4) sid: resolved (fixed in 0.11-4) trixie: resolved (fixed in 0.11-4)
debian