668
VMScore

CVE-2016-4303

Published: 26/09/2016 Updated: 30/06/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote malicious users to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

iperf3 project iperf3

novell suse package hub for suse linux enterprise 12

opensuse leap 42.1

opensuse opensuse 13.2

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #827116 iperf3: CVE-2016-4303: JSON parsing vulnerability Package: src:iperf3; Maintainer for src:iperf3 is Roberto Lumbreras <rover@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 12 Jun 2016 12:57:01 UTC Severity: grave Tags: fixed-upstream, security, upstream ...