UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 06:33
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=36009 - Exploit, Issue Tracking, Third Party Advisory | |
References | () https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ujson/OSV-2021-955.yaml - Exploit, Third Party Advisory | |
References | () https://github.com/ultrajson/ultrajson/issues/501 - Exploit, Issue Tracking, Third Party Advisory | |
References | () https://github.com/ultrajson/ultrajson/issues/502#issuecomment-1031747284 - Issue Tracking, Patch, Third Party Advisory | |
References | () https://github.com/ultrajson/ultrajson/pull/504 - Patch, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2022/02/msg00023.html - Mailing List, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CN7W3GOXALINKFUUE7ICQIC2EF5HNKUQ/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NAU5N4A7EUK2AMUCOLYDD5ARXAJYZBD2/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O6JUWQTJLA2CMG4CJN7DCUVSOXLZIIXL/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ULX35TSWLBBIMEH44MUORPXYYRZKEDC6/ - |
07 Nov 2023, 03:39
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2022-01-01 00:15
Updated : 2024-11-21 06:33
NVD link : CVE-2021-45958
Mitre link : CVE-2021-45958
CVE.ORG link : CVE-2021-45958
JSON object : View
Products Affected
fedoraproject
- fedora
ultrajson_project
- ultrajson
debian
- debian_linux
CWE
CWE-787
Out-of-bounds Write