Input validation error in jansson - CVE-2016-4425
Published: May 17, 2016 / Updated: August 3, 2020
Vulnerability identifier: #VU33275
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4425
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Jansson 2.7 and earlier allows context-dependent attackers to cause a denial of service (deep recursion, stack consumption, and crash) via crafted JSON data.
Affected software
jansson
Arch Linux
Fedora
jansson (Alpine package)
jansson
Arch Linux
Fedora
jansson (Alpine package)
jansson
How to mitigate CVE-2016-4425
Install update from vendor's website.
jansson - update to 2.9
jansson (Alpine package) - update to 2.7-r1
jansson - addressed in versions 2.9-1.el6, 2.9-1.fc23, 2.9-1.fc24, 2.9-1.fc25
jansson (Alpine package) - update to 2.7-r1
jansson - addressed in versions 2.9-1.el6, 2.9-1.fc23, 2.9-1.fc24, 2.9-1.fc25
External References
- http://www.debian.org/security/2015/dsa-3577
- http://www.openwall.com/lists/oss-security/2016/05/01/5
- http://www.openwall.com/lists/oss-security/2016/05/02/1
- http://www.openwall.com/lists/oss-security/2016/05/03/3
- https://github.com/akheron/jansson/issues/282
- https://github.com/akheron/jansson/pull/284
- https://github.com/akheron/jansson/pull/284/commits/64ce0ad3731ebd77e02897b07920eadd0e2cc318