CVE-2020-12762

Updated on 09 May 2020

Severity

7.8 High severity

Details

CVSS score
7.8
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Overview

About vulnerability

json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

Details

Affected product:
AlmaLinux 9.2 ESU , CentOS 8.5 ELS
Affected packages:
libfastjson @ 0.99.9 (+2 more)
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

Fixes