PT-2023-31573 · Cjson+5 · Cjson+5

Alan Wang

·

Published

2023-12-14

·

Updated

2025-08-19

·

CVE-2023-50472

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions cJSON version 1.7.16
Description The issue is related to a segmentation violation in the function cJSON SetValuestring at cJSON.c. This indicates a potential problem with memory access that could lead to a crash or other unintended behavior. No information is provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For cJSON version 1.7.16, consider avoiding the use of the cJSON SetValuestring function until a patch is available. As a temporary workaround, restricting access to the cJSON.c file or the cJSON SetValuestring function could help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2024-17682
ALT-PU-2025-8167
AZL-32207
AZL-67467
BDU:2025-10850
CVE-2023-50472
MGASA-2024-0156
OESA-2024-2302
OESA-2024-2303
OPENSUSE-SU-2024:0139-1
OPENSUSE-SU-2024:13537-1
RHSA-2025:9838
USN-6784-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Red Os
Ubuntu
Cjson