PT-2024-10424 · Cjson+4 · Cjson+4
Up-Wind
·
Published
2024-03-25
·
Updated
2025-08-19
·
CVE-2024-31755
CVSS v2.0
8.0
High
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
cJSON version 1.7.17
Description
The issue is related to a segmentation violation that can be triggered through the second parameter of the
cJSON SetValuestring function at cJSON.c. This can lead to a denial of service. The vulnerability is associated with null pointer dereference errors in the cJSON SetValuestring function of the cJSON library for working with JSON objects in C. Exploitation of the vulnerability may allow a remote attacker to cause a denial of service.Recommendations
For cJSON version 1.7.17, as a temporary workaround, consider disabling the
cJSON SetValuestring function until a patch is available. Restrict access to the cJSON.c component to minimize the risk of exploitation. Avoid using the second parameter of the cJSON SetValuestring function in the affected cJSON.c file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Red Os
Ubuntu
Cjson