CVE-2016-4303
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.96%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 6.96% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- es/iperf3 · novell/suse package hub for suse linux enterprise · opensuse/leap · opensuse/opensuse · debian/debian linux
- Source
- cret@cert.org
References
- http://blog.talosintel.com/2016/06/esnet-vulnerability.htmlExploit, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-08/msg00082.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-08/msg00090.htmlMailing List, Third Party Advisory
- http://software.es.net/iperf/news.html#security-issue-iperf-3-1-3-iperf-3-0-12-releasedRelease Notes, Third Party Advisory
- http://www.talosintelligence.com/reports/TALOS-2016-0164/Exploit, Third Party Advisory
- https://github.com/esnet/iperf/commit/91f2fa59e8ed80dfbf400add0164ee0e508e412aPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00023.htmlMailing List, Third Party Advisory
- https://raw.githubusercontent.com/esnet/security/master/cve-2016-4303/esnet-secadv-2016-0001.txt.ascThird Party Advisory
- http://blog.talosintel.com/2016/06/esnet-vulnerability.htmlExploit, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-08/msg00082.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-08/msg00090.htmlMailing List, Third Party Advisory
- http://software.es.net/iperf/news.html#security-issue-iperf-3-1-3-iperf-3-0-12-releasedRelease Notes, Third Party Advisory
- http://www.talosintelligence.com/reports/TALOS-2016-0164/Exploit, Third Party Advisory
- https://github.com/esnet/iperf/commit/91f2fa59e8ed80dfbf400add0164ee0e508e412aPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00023.htmlMailing List, Third Party Advisory
- https://raw.githubusercontent.com/esnet/security/master/cve-2016-4303/esnet-secadv-2016-0001.txt.ascThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.