PT-2023-31573 · Cjson+5 · Cjson+5
Alan Wang
·
Published
2023-12-14
·
Updated
2025-08-19
·
CVE-2023-50472
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
cJSON version 1.7.16
Description
The issue is related to a segmentation violation in the function
cJSON SetValuestring at cJSON.c. This indicates a potential problem with memory access that could lead to a crash or other unintended behavior. No information is provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.Recommendations
For cJSON version 1.7.16, consider avoiding the use of the
cJSON SetValuestring function until a patch is available. As a temporary workaround, restricting access to the cJSON.c file or the cJSON SetValuestring function could help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Red Os
Ubuntu
Cjson