Stack-based buffer overflow in ultrajson - CVE-2021-45958
Published: April 6, 2022
Vulnerability identifier: #VU61917
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-45958
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Buffer_AppendIndentUnchecked. A remote unauthenticated attacker can trigger stack-based buffer overflow and cause a denial of service condition on the target system.
Affected software
ultrajson
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
Development Tools Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
Fedora
FastAPI
Cloud Pak for Security (CP4S)
python3-ujson (Ubuntu package)
python-ujson (Ubuntu package)
python-fastapi
python2-ujson
python2-ujson-debuginfo
python3-ujson
python-ujson-debuginfo
python-ujson-debugsource
python3-ujson-debuginfo
python-ujson
QRadar Assistant
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
Development Tools Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
Fedora
FastAPI
Cloud Pak for Security (CP4S)
python3-ujson (Ubuntu package)
python-ujson (Ubuntu package)
python-fastapi
python2-ujson
python2-ujson-debuginfo
python3-ujson
python-ujson-debuginfo
python-ujson-debugsource
python3-ujson-debuginfo
python-ujson
QRadar Assistant
How to mitigate CVE-2021-45958
Install update from vendor's website.
ultrajson - update to 5.2.0
FastAPI - update to 0.75.2
Cloud Pak for Security (CP4S) - update to 1.10.7.0
python3-ujson (Ubuntu package) - addressed in versions Ubuntu Pro, 1.35-4ubuntu0.1
python-ujson (Ubuntu package) - update to Ubuntu Pro
python-fastapi - addressed in versions 0.75.0-3.fc36, 0.75.2-1.fc36
python2-ujson - update to 1.35-150100.3.8.1
python2-ujson-debuginfo - update to 1.35-150100.3.8.1
python3-ujson - update to 1.35-150100.3.8.1
python-ujson-debuginfo - update to 1.35-150100.3.8.1
python-ujson-debugsource - update to 1.35-150100.3.8.1
python3-ujson-debuginfo - update to 1.35-150100.3.8.1
QRadar Assistant - update to 3.7.0
python-ujson - addressed in versions 5.1.0-1.fc36, 5.2.0-1.fc36, 5.4.0-1.fc35
FastAPI - update to 0.75.2
Cloud Pak for Security (CP4S) - update to 1.10.7.0
python3-ujson (Ubuntu package) - addressed in versions Ubuntu Pro, 1.35-4ubuntu0.1
python-ujson (Ubuntu package) - update to Ubuntu Pro
python-fastapi - addressed in versions 0.75.0-3.fc36, 0.75.2-1.fc36
python2-ujson - update to 1.35-150100.3.8.1
python2-ujson-debuginfo - update to 1.35-150100.3.8.1
python3-ujson - update to 1.35-150100.3.8.1
python-ujson-debuginfo - update to 1.35-150100.3.8.1
python-ujson-debugsource - update to 1.35-150100.3.8.1
python3-ujson-debuginfo - update to 1.35-150100.3.8.1
QRadar Assistant - update to 3.7.0
python-ujson - addressed in versions 5.1.0-1.fc36, 5.2.0-1.fc36, 5.4.0-1.fc35
External References
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ujson/OSV-2021-955.yaml
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=36009
- https://github.com/ultrajson/ultrajson/issues/501
- https://github.com/ultrajson/ultrajson/issues/502#issuecomment-1031747284
- https://github.com/ultrajson/ultrajson/pull/504
- https://lists.debian.org/debian-lts-announce/2022/02/msg00023.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CN7W3GOXALINKFUUE7ICQIC2EF5HNKUQ/
Related Security Bulletins
- Denial of service in ultrajson
- Stack-based buffer overflow in fastapi
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- SUSE update for python-ujson
- Ubuntu update for ujson
- Ubuntu update for ujson
- Ubuntu update for ujson
- Multiple vulnerabilities in IBM QRadar Assistant
- Fedora 36 update for python-fastapi, python-ujson
- Fedora 36 update for python-fastapi
- Fedora 36 update for python-ujson
- Fedora 35 update for python-ujson