Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 14.04: USN-2245-1 json-c Denial Of Service Warning

ubuntu
Calendar Grey June 12, 2014
Scroller Ubuntu
json-c vulnerabilities identified in Ubuntu 14.04, 13.10, and 12.04 leading to service disruption. Update now!
json-c could be made to crash or consume CPU if it processed a specially crafted JSON document.

Summary

json-c could be made to crash or consume CPU if it processed a specially

crafted JSON document.

Software Description:

- json-c: JSON manipulation library

Details:

Florian Weimer discovered that json-c incorrectly handled buffer lengths.

An attacker could use this issue with a specially-crafted large JSON

document to cause json-c to crash, resulting in a denial of service.

(CVE-2013-6370)

Florian Weimer discovered that json-c incorrectly handled hash arrays. An

attacker could use this issue with a specially-crafted JSON document to

cause json-c to consume CPU resources, resulting in a denial of service.

(CVE-2013-6371)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  libjson0                        0.11-3ubuntu1.2

Ubuntu 13.10:
  libjson0                        0.11-2ubuntu1.2

Ubuntu 12.04 LTS:
  libjson0                        0.9-1ubuntu1.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2245-1

CVE-2013-6370, CVE-2013-6371

Severity
critical
Lowest
Low
Medium
High
Critical

June 12, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.