Stack-based buffer overflow in ultrajson - CVE-2021-45958

 

Stack-based buffer overflow in ultrajson - CVE-2021-45958

Published: April 6, 2022


Vulnerability identifier: #VU61917
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-45958
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in Buffer_AppendIndentUnchecked. A remote unauthenticated attacker can trigger stack-based buffer overflow and cause a denial of service condition on the target system.


Affected software

ultrajson
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
Development Tools Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
Fedora
FastAPI
Cloud Pak for Security (CP4S)
python3-ujson (Ubuntu package)
python-ujson (Ubuntu package)
python-fastapi
python2-ujson
python2-ujson-debuginfo
python3-ujson
python-ujson-debuginfo
python-ujson-debugsource
python3-ujson-debuginfo
python-ujson
QRadar Assistant

How to mitigate CVE-2021-45958

Install update from vendor's website.

ultrajson - update to 5.2.0
FastAPI - update to 0.75.2
Cloud Pak for Security (CP4S) - update to 1.10.7.0
python3-ujson (Ubuntu package) - addressed in versions Ubuntu Pro, 1.35-4ubuntu0.1
python-ujson (Ubuntu package) - update to Ubuntu Pro
python-fastapi - addressed in versions 0.75.0-3.fc36, 0.75.2-1.fc36
python2-ujson - update to 1.35-150100.3.8.1
python2-ujson-debuginfo - update to 1.35-150100.3.8.1
python3-ujson - update to 1.35-150100.3.8.1
python-ujson-debuginfo - update to 1.35-150100.3.8.1
python-ujson-debugsource - update to 1.35-150100.3.8.1
python3-ujson-debuginfo - update to 1.35-150100.3.8.1
QRadar Assistant - update to 3.7.0
python-ujson - addressed in versions 5.1.0-1.fc36, 5.2.0-1.fc36, 5.4.0-1.fc35

External References

Related Security Bulletins