5
CVSSv2

CVE-2013-6401

Published: 21/03/2014 Updated: 23/05/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Jansson, possibly 2.4 and previous versions, does not restrict the ability to trigger hash collisions predictably, which allows context-dependent malicious users to cause a denial of service (CPU consumption) via a crafted JSON document.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jansson project jansson 2.3

jansson project jansson

jansson project jansson 2.3.1

jansson project jansson 2.0

jansson project jansson 2.0.1

jansson project jansson 2.2

jansson project jansson 2.2.1

jansson project jansson 2.1

Vendor Advisories

Debian Bug report logs - #738647 jansson: CVE-2013-6401: hash collision issue Package: jansson; Maintainer for jansson is Alessandro Ghedini <ghedo@debianorg>; Reported by: Henri Salo <henri@nervfi> Date: Tue, 11 Feb 2014 14:57:01 UTC Severity: important Tags: fixed-upstream, security Found in versions 25-2, 23 ...
Jansson, possibly 24 and earlier, does not restrict the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted JSON document ...