PT-2025-4004 · Cesanta · Cesanta Frozen
Diego Zaffaroni
·
Published
2025-01-27
·
Updated
2025-01-27
·
CVE-2025-0695
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Cesanta Frozen versions less than 1.7
Description
An Allocation of Resources Without Limits or Throttling issue allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON as input.
Recommendations
For Cesanta Frozen versions less than 1.7, update to version 1.7 or later to resolve the issue. As a temporary workaround, consider validating and sanitizing all JSON inputs to prevent maliciously crafted data from being processed. Restrict access to components that embed the Cesanta Frozen library to minimize the risk of exploitation.
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cesanta Frozen