CVE-2018-1000216
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker must be able to force victim to print JSON data, depending on how cJSON library is used this could be either local or over a network. This vulnerability appears to have been fixed in 1.7.3.
Dave Gamble cJSON en versiones 1.7.2 y anteriores contiene una vulnerabilidad CWE-415: Doble liberación (double free) en la librería cJSON que puede resultar en un posible cierre inesperado o RCE. Este ataque parece ser explotable si el atacante puede forzar a la víctima a que imprima datos JSON. Dependiendo de cómo se utiliza la librería cJSON, esto se puede conseguir de manera local o a través de la red. La vulnerabilidad parece haber sido solucionada en la versión 1.7.3.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-08-20 CVE Reserved
- 2018-08-20 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- 2024-09-17 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-415: Double Free
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/DaveGamble/cJSON/issues/241 | 2024-09-17 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cjson Project Search vendor "Cjson Project" | Cjson Search vendor "Cjson Project" for product "Cjson" | < 1.7.3 Search vendor "Cjson Project" for product "Cjson" and version " < 1.7.3" | - |
Affected
|