FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

json-c -- integer overflow and out-of-bounds write via a large JSON file

Affected packages
json-c < 0.14


VuXML ID abc3ef37-95d4-11ea-9004-25fadb81abf4
Discovery 2020-05-02
Entry 2020-05-14
Modified 2020-05-17

Tobias Stöckmann reports:

I have discovered a way to trigger an out of boundary write while parsing a huge json file through a malicious input source. It can be triggered if an attacker has control over the input stream or if a huge load during filesystem operations can be triggered.


CVE Name CVE-2020-12762