PT-2010-3326 · Unknown · Python-Cjson

Matt Giuca

+1

·

Publicado

2010-07-02

·

Atualizado

2022-05-17

·

CVE-2010-1666

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions python-cjson version 1.0.5
Description The issue is related to a buffer overflow that occurs when UCS-4 encoding is enabled. This allows attackers to cause a denial of service, resulting in an application crash, or possibly have other unspecified impacts. The attack vectors involve crafted Unicode input to the cjson.encode function.
Recommendations For python-cjson version 1.0.5, consider disabling UCS-4 encoding as a temporary workaround to minimize the risk of exploitation. Avoid using the cjson.encode function with crafted Unicode input until the issue is resolved.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1666
DSA-2068-1
GHSA-CQMH-MPX2-G633
PYSEC-2010-30

Produtos afetados

Python-Cjson