CVE-2022-23459
Double free or Use after Free in Value class of Jsonxx
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx use of the Value class may lead to memory corruption via a double free or via a use after free. The value class has a default assignment operator which may be used with pointer types which may point to alterable data where the pointer itself is not updated. This issue exists on the current commit of the jsonxx project. The project itself has been archived and updates are not expected. Users are advised to find a replacement.
Jsonxx o Json++ es un analizador, escritor y lector de JSON escrito en C++. En versiones afectadas de jsonxx el uso de la clase Value puede conllevar a una corrupción de memoria por medio de una doble liberación o de un uso de memoria previamente liberada. La clase Value presenta un operador de asignación por defecto que puede ser usado con tipos de punteros que pueden apuntar a datos alterables donde el propio puntero no es actualizado. Este problema se presenta en el commit actual del proyecto jsonxx. El proyecto en sí ha sido archivado y no son esperadas actualizaciones. Es recomendado a usuarios buscar un sustituto.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-19 CVE Reserved
- 2022-08-19 CVE Published
- 2024-03-11 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-415: Double Free
- CWE-416: Use After Free
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://securitylab.github.com/advisories/GHSL-2022-048_Jsonxx | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Json\+\+ Project Search vendor "Json\+\+ Project" | Json\+\+ Search vendor "Json\+\+ Project" for product "Json\+\+" | 1.0.0 Search vendor "Json\+\+ Project" for product "Json\+\+" and version "1.0.0" | - |
Affected
| ||||||
Json\+\+ Project Search vendor "Json\+\+ Project" | Json\+\+ Search vendor "Json\+\+ Project" for product "Json\+\+" | 1.0.1 Search vendor "Json\+\+ Project" for product "Json\+\+" and version "1.0.1" | - |
Affected
|