Lucene search

K
redhatcveRedhat.comRH:CVE-2020-12762
HistoryMay 13, 2020 - 2:10 p.m.

CVE-2020-12762

2020-05-1314:10:37
redhat.com
access.redhat.com
15

0.001 Low

EPSS

Percentile

44.7%

A flaw was found in json-c. In printbuf_memappend, certain crafted values can overflow the memory allowing an attacker to write past the memory boundary. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Mitigation

Since this flaw is triggered by untrusted large json files. If any applications linked against json-c is used ensure that the application does not accept large json files. (or untrusted ones wherever possible)