Vulnerability CVE-2020-12762: Information

Description

json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

Severity: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: May 9, 2020
Modified: Nov. 7, 2023
Error type identifier: CWE-787CWE-190

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
json-csisyphus0.14-alt20.17-alt1ALT-PU-2020-2307-1254506Fixed
json-cp100.17-alt10.17-alt1ALT-PU-2023-6481-3332180Fixed
json-cp90.13.1-alt20.13.1-alt2ALT-PU-2020-2322-2254507Fixed
json-cc10f10.17-alt10.17-alt1ALT-PU-2023-6841-4333296Fixed
json-cc9f20.13.1-alt20.13.1-alt2ALT-PU-2020-2322-2254507Fixed
libfastjsonsisyphus1.2304.0-alt11.2304.0-alt1ALT-PU-2023-6478-1332173Fixed
libfastjsonsisyphus_e2k1.2304.0-alt11.2304.0-alt1ALT-PU-2023-6539-1-Fixed
libfastjsonsisyphus_riscv641.2304.0-alt11.2304.0-alt1ALT-PU-2023-6534-1-Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:json-c:json-c:*:*:*:*:*:*:*:*
      End excliding
      0.15-20200726

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*

      Configuration 5

      cpe:2.3:a:siemens:sinec_ins:1.0:sp1:*:*:*:*:*:*

      cpe:2.3:a:siemens:sinec_ins:1.0:-:*:*:*:*:*:*

      cpe:2.3:a:siemens:sinec_ins:-:*:*:*:*:*:*:*