Vulnerability CVE-2020-12762: Information
Description
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: MEDIUM (6.8)
Vector: CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
Published: May 9, 2020
Modified: Nov. 3, 2025
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
|---|---|---|---|---|---|---|
| json-c | sisyphus | 0.14-alt2 | 0.18-alt1 | ALT-PU-2020-2307-1 | 254506 | Fixed |
| json-c | p11 | 0.14-alt2 | 0.18-alt1 | ALT-PU-2020-2307-1 | 254506 | Fixed |
| json-c | p10 | 0.17-alt1 | 0.17-alt1 | ALT-PU-2023-6481-3 | 332180 | Fixed |
| json-c | p9 | 0.13.1-alt2 | 0.13.1-alt2 | ALT-PU-2020-2322-2 | 254507 | Fixed |
| json-c | c10f2 | 0.17-alt1 | 0.18-alt0.c10.1 | ALT-PU-2023-6480-3 | 332181 | Fixed |
| json-c | c9f2 | 0.13.1-alt2 | 0.13.1-alt2 | ALT-PU-2020-2322-2 | 254507 | Fixed |
| libfastjson | sisyphus | 1.2304.0-alt1 | 1.2304.0-alt1 | ALT-PU-2023-6478-1 | 332173 | Fixed |
| libfastjson | sisyphus_e2k | 1.2304.0-alt1 | 1.2304.0-alt1 | ALT-PU-2023-6539-1 | - | Fixed |
| libfastjson | sisyphus_riscv64 | 1.2304.0-alt1 | 1.2304.0-alt1 | ALT-PU-2023-6534-1 | - | Fixed |
| libfastjson | p11 | 1.2304.0-alt1 | 1.2304.0-alt1 | ALT-PU-2023-6478-1 | 332173 | Fixed |