USN-2245-1

Source
https://ubuntu.com/security/notices/USN-2245-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-2245-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-2245-1
Related
Published
2014-06-12T16:30:16.150565Z
Modified
2014-06-12T16:30:16.150565Z
Summary
json-c vulnerabilities
Details

Florian Weimer discovered that json-c incorrectly handled buffer lengths. An attacker could use this issue with a specially-crafted large JSON document to cause json-c to crash, resulting in a denial of service. (CVE-2013-6370)

Florian Weimer discovered that json-c incorrectly handled hash arrays. An attacker could use this issue with a specially-crafted JSON document to cause json-c to consume CPU resources, resulting in a denial of service. (CVE-2013-6371)

References

Affected packages

Ubuntu:14.04:LTS / json-c

Package

Name
json-c
Purl
pkg:deb/ubuntu/json-c@0.11-3ubuntu1.2?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.11-3ubuntu1.2

Affected versions

0.*

0.11-2ubuntu1
0.11-3ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "0.11-3ubuntu1.2",
            "binary_name": "libjson-c-dev"
        },
        {
            "binary_version": "0.11-3ubuntu1.2",
            "binary_name": "libjson-c-doc"
        },
        {
            "binary_version": "0.11-3ubuntu1.2",
            "binary_name": "libjson-c2"
        },
        {
            "binary_version": "0.11-3ubuntu1.2",
            "binary_name": "libjson-c2-dbg"
        },
        {
            "binary_version": "0.11-3ubuntu1.2",
            "binary_name": "libjson0"
        },
        {
            "binary_version": "0.11-3ubuntu1.2",
            "binary_name": "libjson0-dev"
        }
    ]
}