USN-2245-1
Dashboard / Vulnerabilities / USN-2245-1
USN-2245-1
Summary: json-c vulnerabilities
Details: Florian Weimer discovered that json-c incorrectly handled buffer lengths. An attacker could use this issue with a specially-crafted large JSON document to cause json-c to crash, resulting in a denial of service. (CVE-2013-6370) Florian Weimer discovered that json-c incorrectly handled hash arrays. An attacker could use this issue with a specially-crafted JSON document to cause json-c to consume CPU resources, resulting in a denial of service. (CVE-2013-6371)
References: https://ubuntu.com/security/notices/USN-2245-1, https://ubuntu.com/security/CVE-2013-6370, https://ubuntu.com/security/CVE-2013-6371
Affected packages
Package
Name: json-c
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
