Bug 2246417 (CVE-2023-5072) - CVE-2023-5072 JSON-java: parser confusion leads to OOM
Summary: CVE-2023-5072 JSON-java: parser confusion leads to OOM
Keywords:
Status: NEW
Alias: CVE-2023-5072
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2246416
TreeView+ depends on / blocked
 
Reported: 2023-10-26 16:35 UTC by Chess Hazlett
Modified: 2024-04-30 23:00 UTC (History)
78 users (show)

Fixed In Version: org.json 20231013
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the org.json package. A bug in the parser exists, and an input string may lead to undefined usage of memory, leading to an out-of-memory error, causing a denial of service (DoS).
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:7617 0 None None None 2023-11-30 15:00:46 UTC
Red Hat Product Errata RHSA-2023:7678 0 None None None 2023-12-06 23:30:47 UTC
Red Hat Product Errata RHSA-2023:7705 0 None None None 2023-12-07 15:32:53 UTC
Red Hat Product Errata RHSA-2023:7842 0 None None None 2023-12-14 10:50:11 UTC
Red Hat Product Errata RHSA-2023:7845 0 None None None 2023-12-14 15:55:01 UTC
Red Hat Product Errata RHSA-2024:0148 0 None None None 2024-01-10 13:30:33 UTC
Red Hat Product Errata RHSA-2024:1353 0 None None None 2024-03-18 09:48:21 UTC

Description Chess Hazlett 2023-10-26 16:35:54 UTC
Denial of Service in JSON-Java versions up to and including 20230618.  A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.

Comment 4 errata-xmlrpc 2023-11-30 15:00:41 UTC
This issue has been addressed in the following products:

  Red Hat Integration

Via RHSA-2023:7617 https://access.redhat.com/errata/RHSA-2023:7617

Comment 5 errata-xmlrpc 2023-12-06 23:30:43 UTC
This issue has been addressed in the following products:

  Red Hat AMQ Streams 2.6.0

Via RHSA-2023:7678 https://access.redhat.com/errata/RHSA-2023:7678

Comment 6 errata-xmlrpc 2023-12-07 15:32:49 UTC
This issue has been addressed in the following products:

  Red Hat Integration

Via RHSA-2023:7705 https://access.redhat.com/errata/RHSA-2023:7705

Comment 7 errata-xmlrpc 2023-12-14 10:50:07 UTC
This issue has been addressed in the following products:

  RHINT Camel-Springboot 4.0.2

Via RHSA-2023:7842 https://access.redhat.com/errata/RHSA-2023:7842

Comment 8 errata-xmlrpc 2023-12-14 15:54:57 UTC
This issue has been addressed in the following products:

  RHINT Camel-Springboot 3.20.4

Via RHSA-2023:7845 https://access.redhat.com/errata/RHSA-2023:7845

Comment 9 errata-xmlrpc 2024-01-10 13:30:29 UTC
This issue has been addressed in the following products:

  RHINT Camel-K 1.10.5

Via RHSA-2024:0148 https://access.redhat.com/errata/RHSA-2024:0148

Comment 12 errata-xmlrpc 2024-03-18 09:48:17 UTC
This issue has been addressed in the following products:

  RHPAM 7.13.5 async

Via RHSA-2024:1353 https://access.redhat.com/errata/RHSA-2024:1353


Note You need to log in before you can comment on or make changes to this bug.