Bug 2246417 (CVE-2023-5072)

Summary: CVE-2023-5072 JSON-java: parser confusion leads to OOM
Product: [Other] Security Response Reporter: Chess Hazlett <chazlett>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aileenc, asoldano, ataylor, bbaranow, bmaxwell, boliveir, brian.stansberry, ccranfor, cdewolf, chazlett, chfoley, cmiranda, darran.lofthouse, davidn, dhanak, dkreling, dosoudil, drichtar, dsimansk, epacific, eric.wittmann, fjuma, fmariani, fmongiar, gmalinko, ibek, ivassile, iweiss, janstey, jcammara, jhardy, jneedle, jnethert, jobarker, jpechane, jpoth, jrokos, jross, jscholz, kverlaen, lball, lgao, mabashia, matzew, mnovotny, mosmerov, msochure, mstefank, msvehla, mulliken, nwallace, pantinor, pcongius, pdelbell, pdrozd, peholase, pjindal, pmackay, pskopek, rguimara, rhuss, rkieley, rowaters, rstancel, simaishi, smaestri, smcdonal, sthorger, swoodman, tcunning, teagle, tom.jenkinson, yfang, yguenane, zsadeh
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: org.json 20231013 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the org.json package. A bug in the parser exists, and an input string may lead to undefined usage of memory, leading to an out-of-memory error, causing a denial of service (DoS).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2246416    

Description Chess Hazlett 2023-10-26 16:35:54 UTC
Denial of Service in JSON-Java versions up to and including 20230618.  A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.

Comment 4 errata-xmlrpc 2023-11-30 15:00:41 UTC
This issue has been addressed in the following products:

  Red Hat Integration

Via RHSA-2023:7617 https://access.redhat.com/errata/RHSA-2023:7617

Comment 5 errata-xmlrpc 2023-12-06 23:30:43 UTC
This issue has been addressed in the following products:

  Red Hat AMQ Streams 2.6.0

Via RHSA-2023:7678 https://access.redhat.com/errata/RHSA-2023:7678

Comment 6 errata-xmlrpc 2023-12-07 15:32:49 UTC
This issue has been addressed in the following products:

  Red Hat Integration

Via RHSA-2023:7705 https://access.redhat.com/errata/RHSA-2023:7705

Comment 7 errata-xmlrpc 2023-12-14 10:50:07 UTC
This issue has been addressed in the following products:

  RHINT Camel-Springboot 4.0.2

Via RHSA-2023:7842 https://access.redhat.com/errata/RHSA-2023:7842

Comment 8 errata-xmlrpc 2023-12-14 15:54:57 UTC
This issue has been addressed in the following products:

  RHINT Camel-Springboot 3.20.4

Via RHSA-2023:7845 https://access.redhat.com/errata/RHSA-2023:7845

Comment 9 errata-xmlrpc 2024-01-10 13:30:29 UTC
This issue has been addressed in the following products:

  RHINT Camel-K 1.10.5

Via RHSA-2024:0148 https://access.redhat.com/errata/RHSA-2024:0148

Comment 12 errata-xmlrpc 2024-03-18 09:48:17 UTC
This issue has been addressed in the following products:

  RHPAM 7.13.5 async

Via RHSA-2024:1353 https://access.redhat.com/errata/RHSA-2024:1353

Comment 14 errata-xmlrpc 2024-05-23 22:45:46 UTC
This issue has been addressed in the following products:

  Red Hat Fuse 7.13.0

Via RHSA-2024:3354 https://access.redhat.com/errata/RHSA-2024:3354

Comment 16 errata-xmlrpc 2024-06-10 12:02:53 UTC
This issue has been addressed in the following products:

  Red Hat JBoss AMQ

Via RHSA-2024:3752 https://access.redhat.com/errata/RHSA-2024:3752

Comment 17 errata-xmlrpc 2024-06-10 14:20:35 UTC
This issue has been addressed in the following products:

  Red Hat JBoss AMQ

Via RHSA-2024:3762 https://access.redhat.com/errata/RHSA-2024:3762

Comment 18 errata-xmlrpc 2024-07-02 16:23:52 UTC
This issue has been addressed in the following products:

  Red Hat JBoss AMQ

Via RHSA-2024:4271 https://access.redhat.com/errata/RHSA-2024:4271

Comment 20 errata-xmlrpc 2025-03-07 11:29:30 UTC
This issue has been addressed in the following products:

  Red Hat AMQ Streams 2.5.2

Via RHSA-2024:6536 https://access.redhat.com/errata/RHSA-2024:6536