Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2020-12762

Published: August 31, 2023Last modified: August 31, 2023

Description

json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

Severity score breakdown

ParameterValue
Base score7.8
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSjson-cNot affected (0.16-r2)
Streamjson-cNot affected (0.17-r0)

References

ON THIS PAGE