Florian Weimer reported that the hash function in the json-c library was weak, and that parsing smallish JSON strings showed quadratic timing behaviour. This could cause an application linked to the json-c library, and that processes some specially-crafted JSON data, to use excessive amounts of CPU.
Acknowledgements:
This issue was discovered by Florian Weimer of the Red Hat Product Security Team.
Comment 2Huzaifa S. Sidhpurwala
2014-04-09 06:18:32 UTC