Bug 2235514 (CVE-2021-32292) - CVE-2021-32292 json-c: stack-buffer-overflow in parseit() in json_parse.c
Summary: CVE-2021-32292 json-c: stack-buffer-overflow in parseit() in json_parse.c
Keywords:
Status: NEW
Alias: CVE-2021-32292
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2236135 2235515 2235516 2235517 2235518 2236136 2236137
Blocks: 2235500
TreeView+ depends on / blocked
 
Reported: 2023-08-28 22:09 UTC by Chess Hazlett
Modified: 2023-10-02 18:51 UTC (History)
2 users (show)

Fixed In Version: json-c 0.16-20220414
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the parseit() function in json_parse.c., a test app in the json-c library. The code error does not affect the library itself.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Chess Hazlett 2023-08-28 22:09:06 UTC
An issue was discovered in json-c through 0.15-20200726. A stack-buffer-overflow exists in the function parseit located in json_parse.c. It allows an attacker to cause code Execution.

https://github.com/json-c/json-c/issues/654

Comment 3 TEJ RATHI 2023-08-30 12:28:39 UTC
Created json-c tracking bugs for this issue:

Affects: fedora-37 [bug 2236136]
Affects: fedora-38 [bug 2236137]


Created json-c12 tracking bugs for this issue:

Affects: epel-7 [bug 2236135]


Note You need to log in before you can comment on or make changes to this bug.