Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
cJSON 安全漏洞
Vulnerability Description
cJSON是一款使用C语言编写的JSON解析器。 cJSON库中的cjson.c文件中的‘parse_string’函数存在安全漏洞,该漏洞源于程序没有正确处理UTF8/16字符串。远程攻击者可借助JSON字符串中的non-hex字符利用该漏洞造成拒绝服务(崩溃)或执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A