CVE-2020-12762: Integer Overflow
json-c could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow and out-of-bounds write. By persuading a victim to run a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Other sources
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbufmemappend.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-12762.
What is the severity of CVE-2020-12762?
The severity of CVE-2020-12762 is high.
Which software products and versions are affected by this vulnerability?
This vulnerability affects IBM QRadar SIEM versions 7.5.0 GA, 7.4.3 GA - 7.4.3 FP4, and 7.3.3 GA - 7.3.3 FP10.
How can I fix CVE-2020-12762?
To fix CVE-2020-12762, you can apply the patches provided by IBM for affected versions of IBM QRadar SIEM.
Where can I find more information about CVE-2020-12762?
You can find more information about CVE-2020-12762 on the following websites: [IBM X-Force Exchange](https://exchange.xforce.ibmcloud.com/vulnerabilities/182094), [IBM Support](https://www.ibm.com/support/pages/node/6574787), [Siemens ProductCERT](https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf).