FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

json-c -- integer overflow and out-of-bounds write via a large JSON file

Affected packages
json-c < 0.14

Details

VuXML ID abc3ef37-95d4-11ea-9004-25fadb81abf4
Discovery 2020-05-02
Entry 2020-05-14
Modified 2020-05-17

Tobias Stöckmann reports:

I have discovered a way to trigger an out of boundary write while parsing a huge json file through a malicious input source. It can be triggered if an attacker has control over the input stream or if a huge load during filesystem operations can be triggered.

References

CVE Name CVE-2020-12762
URL https://github.com/json-c/json-c/pull/592
URL https://github.com/json-c/json-c/pull/599