An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/json-c/json-c/issues/654 | exploit issue tracking |
https://www.debian.org/security/2023/dsa-5486 | third party advisory vendor advisory |
https://security.netapp.com/advisory/ntap-20230929-0010/ | third party advisory |