Cryptographic issues in jansson - CVE-2013-6401
Published: March 21, 2014 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Jansson, possibly 2.4 and earlier, does not restrict the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted JSON document.
Affected software
jansson (Alpine package)
jansson
Fedora
IBM DataPower Gateway
How to mitigate CVE-2013-6401
IBM DataPower Gateway - addressed in versions 10.5.0.20, 10.6.0.8, 10.6.6.0
jansson - update to 2.6-1.el6