Stack-based buffer overflow in json-c - CVE-2021-32292
Published: August 29, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the parseit() function in json_parse.c. A remote attacker can pass specially crafted input to the application, trigger a stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Debian Linux
Gentoo Linux
openEuler
Ubuntu
Isolation Segment
VMware Tanzu Application Service for VMs
json-c (Debian package)
libjson-c5 (Ubuntu package)
json-c-debugsource
json-c-help
json-c-debuginfo
json-c-devel
json-c
dev-libs/json-c
VMware Tanzu Operations Manager
HPE Moonshot 1500 Chassis Manager
How to mitigate CVE-2021-32292
json-c (Debian package) - update to 0.15-2+deb11u1
libjson-c5 (Ubuntu package) - update to 0.15-3~ubuntu1.22.04.2
json-c-debugsource - update to 0.15-6
json-c-help - update to 0.15-6
json-c-debuginfo - update to 0.15-6
json-c-devel - update to 0.15-6
json-c - update to 0.15-6
dev-libs/json-c - update to 0.16
VMware Tanzu Operations Manager - update to 3.0.15
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
External References
Related Security Bulletins
- Remote code execution in json-c for Node.js
- Ubuntu update for json-c
- Debian update for json-c
- VMware Tanzu products update for json-c
- openEuler 20.03 LTS SP1 update for json-c
- openEuler 20.03 LTS SP3 update for json-c
- openEuler 22.03 LTS update for json-c
- Gentoo update for json-c
- Multiple vulnerabilities in HPE Moonshot 1500 Chassis Manager