CVE-2021-32292: Critical severity Json-c Project Json-c vulnerability
An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program jsonparse which is located in the function parseit.
Other sources
An issue was discovered in json-c through 0.15-20200726. A stack-buffer-overflow exists in the function parseit located in jsonparse.c. It allows an attacker to cause code Execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32292?
CVE-2021-32292 is classified as a high severity vulnerability due to the potential for remote code execution resulting from the stack-buffer-overflow.
How do I fix CVE-2021-32292?
To mitigate CVE-2021-32292, users should upgrade to json-c version 0.16 or later.
What software is affected by CVE-2021-32292?
CVE-2021-32292 affects json-c versions 0.12.1+ds-2+deb10u1, 0.15-2+deb11u1, 0.16-2, and 0.17-1, among others.
What type of vulnerability is CVE-2021-32292?
CVE-2021-32292 is identified as a stack-buffer-overflow vulnerability.
Can CVE-2021-32292 be exploited remotely?
Yes, CVE-2021-32292 can potentially be exploited remotely, leading to unauthorized execution of code.