PT-2025-4005 · Cesanta · Cesanta Frozen
Diego Zaffaroni
·
Published
2025-01-27
·
Updated
2025-01-27
·
CVE-2025-0696
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Cesanta Frozen versions prior to 1.7
Description
A NULL Pointer Dereference vulnerability allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON as input.
Recommendations
For versions prior to 1.7, update to version 1.7 or later to resolve the issue. As a temporary workaround, consider restricting the input of JSON data to prevent maliciously crafted JSON from being processed by the library.
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cesanta Frozen