PT-2025-35723 · Cjson+5 · Cjson+5
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
cJSON versions 1.5.0 through 1.7.18
Description
cJSON versions 1.5.0 through 1.7.18 contain an out-of-bounds access issue within the
decode array index from pointer function located in cJSON Utils.c. This allows attackers to bypass array bounds checking and potentially access restricted data by providing malformed JSON pointer strings that include alphanumeric characters.Recommendations
Update cJSON to a version later than 1.7.18.
Exploit
Fix
DoS
RCE
Improper Validation of Array Index
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
Red Os
Ubuntu
Cjson