2022-01-01 00:01:03 +00:00
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org" ,
"ID" : "CVE-2021-45958" ,
"STATE" : "PUBLIC"
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "n/a" ,
"version" : {
"version_data" : [
{
"version_value" : "n/a"
}
]
}
}
]
} ,
"vendor_name" : "n/a"
}
]
}
} ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2022-02-07 22:01:21 +00:00
"value" : "UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation."
2022-01-01 00:01:03 +00:00
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "n/a"
}
]
}
]
} ,
"references" : {
"reference_data" : [
{
"url" : "https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ujson/OSV-2021-955.yaml" ,
"refsource" : "MISC" ,
"name" : "https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ujson/OSV-2021-955.yaml"
} ,
{
"url" : "https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=36009" ,
"refsource" : "MISC" ,
"name" : "https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=36009"
2022-02-07 22:01:21 +00:00
} ,
{
"refsource" : "MISC" ,
"name" : "https://github.com/ultrajson/ultrajson/issues/502#issuecomment-1031747284" ,
"url" : "https://github.com/ultrajson/ultrajson/issues/502#issuecomment-1031747284"
} ,
{
"refsource" : "MISC" ,
"name" : "https://github.com/ultrajson/ultrajson/issues/501" ,
"url" : "https://github.com/ultrajson/ultrajson/issues/501"
2022-02-13 21:01:07 +00:00
} ,
{
"refsource" : "CONFIRM" ,
"name" : "https://github.com/ultrajson/ultrajson/pull/504" ,
"url" : "https://github.com/ultrajson/ultrajson/pull/504"
2022-02-27 00:01:10 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[debian-lts-announce] 20220226 [SECURITY] [DLA 2929-1] ujson security update" ,
"url" : "https://lists.debian.org/debian-lts-announce/2022/02/msg00023.html"
2022-03-26 18:01:18 +00:00
} ,
{
"refsource" : "FEDORA" ,
"name" : "FEDORA-2022-dbf6e00ba8" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CN7W3GOXALINKFUUE7ICQIC2EF5HNKUQ/"
2022-05-07 08:01:25 +00:00
} ,
{
"refsource" : "FEDORA" ,
"name" : "FEDORA-2022-569b6b45e2" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ULX35TSWLBBIMEH44MUORPXYYRZKEDC6/"
} ,
{
"refsource" : "FEDORA" ,
"name" : "FEDORA-2022-d1452fd421" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O6JUWQTJLA2CMG4CJN7DCUVSOXLZIIXL/"
2022-08-03 04:00:45 +00:00
} ,
{
"refsource" : "FEDORA" ,
"name" : "FEDORA-2022-33e816bc37" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NAU5N4A7EUK2AMUCOLYDD5ARXAJYZBD2/"
2022-01-01 00:01:03 +00:00
}
]
}
}