GHSA-fm67-cv37-96ff
Dashboard / Vulnerabilities / GHSA-fm67-cv37-96ff
GHSA-fm67-cv37-96ff
Summary: Potential double free of buffer during string decoding
Details: ### Impact _What kind of vulnerability is it? Who is impacted?_ When an error occurs while reallocating the buffer for string decoding, the buffer gets freed twice. Due to how UltraJSON uses the internal decoder, this double free is impossible to trigger from Python. ### Patches _Has the problem been patched? What versions should users upgrade to?_ Users should upgrade to UltraJSON 5.4.0. ### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ There is no workaround. ### For more information If you have any questions or comments about this advisory: * Open an issue in [UltraJSON](http://github.com/ultrajson/ultrajson/issues)
References: https://github.com/ultrajson/ultrajson/security/advisories/GHSA-fm67-cv37-96ff, https://nvd.nist.gov/vuln/detail/CVE-2022-31117, https://github.com/ultrajson/ultrajson/commit/9c20de0f77b391093967e25d01fb48671104b15b, https://github.com/ultrajson/ultrajson, https://lists.fedoraproject.org/archives/list/[email protected]/message/NAU5N4A7EUK2AMUCOLYDD5ARXAJYZBD2, https://lists.fedoraproject.org/archives/list/[email protected]/message/OPPU5FZP3LCTXYORFH7NHUMYA5X66IA7
Affected packages
Package
Name: ujson
Purl: pkg:pypi/ujson
Affected ranges
Type: ECOSYSTEM
Events:
