Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
RapidJSON could be made to crash or run programs as an administrator if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-8189-1 April 20, 2026 rapidjson vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: RapidJSON could be made to crash or run programs as an administrator if it opened a specially crafted file. Software Description: - rapidjson: A fast JSON parser/generator for C++ Details: It was discovered that RapidJSON did not properly protect against integer overflows in certain instances when parsing JSON text. A remote attacker could possibly use this issue to craft a malicious JSON file, that when read by RapidJSON, would lead to an elevation of privilege, resulting in the potential disclosure of sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS rapidjson-dev 1.1.0+dfsg2-7.2ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 22.04 LTS rapidjson-dev 1.1.0+dfsg2-7ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 20.04 LTS rapidjson-dev 1.1.0+dfsg2-5ubuntu1+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS rapidjson-dev 1.1.0+dfsg2-3ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS rapidjson-dev 0.12~git20141031-3ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8189-1 CVE-2024-39684 . RapidJSON in Ubuntucould crash or run programs due to integer overflow, urging updates for security measures.. Ubuntu Security Notice, RapidJSON, JSON Parser Security, Elevation of Privilege, Integer Overflow. . Severity: Important. LinuxSecurity.com Team
Tencent RapidJSON is vulnerable to privilege escalation due to an integer underflow in the `GenericReader::ParseNumber()` function of `include/rapidjson/reader.h` when parsing JSON text from a stream. An attacker needs to send the victim a crafted file which needs to be opened; this triggers the integer underflow vulnerability (when the file . MGASA-2024-0371 - Updated rapidjson packages fix security vulnerability Publication date: 27 Nov 2024 URL: https://advisories.mageia.org/MGASA-2024-0371.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-38517 Tencent RapidJSON is vulnerable to privilege escalation due to an integer underflow in the `GenericReader::ParseNumber()` function of `include/rapidjson/reader.h` when parsing JSON text from a stream. An attacker needs to send the victim a crafted file which needs to be opened; this triggers the integer underflow vulnerability (when the file is parsed), leading to elevation of privilege. (CVE-2024-38517) References: - https://bugs.mageia.org/show_bug.cgi?id=33803 - https://ubuntu.com/security/notices/USN-7125-1 - https://www.cve.org/CVERecord?id=CVE-2024-38517 SRPMS: - 9/core/rapidjson-1.1.0-6.1.mga9 . Recent updates to the rapidjson packages in Mageia address a significant privilege escalation vulnerability. For comprehensive information, see MGASA-2024-0371.. rapidjson vulnerability, privilege escalation, Mageia security advisory. . Severity: Critical. LinuxSecurity.com Team
Fix for CVE-2024-38517.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-a3c1b2629e 2024-07-19 02:21:03.764679 -------------------------------------------------------------------------------- Name : rapidjson Product : Fedora 39 Version : 1.1.0 Release : 41.fc39 URL : http://rapidjson.org/ Summary : Fast JSON parser and generator for C++ Description : RapidJSON is a fast JSON parser and generator for C++. It was inspired by RapidXml. RapidJSON is small but complete. It supports both SAX and DOM style API. The SAX parser is only a half thousand lines of code. RapidJSON is fast. Its performance can be comparable to strlen(). It also optionally supports SSE2/SSE4.1 for acceleration. RapidJSON is self-contained. It does not depend on external libraries such as BOOST. It even does not depend on STL. RapidJSON is memory friendly. Each JSON value occupies exactly 16/20 bytes for most 32/64-bit machines (excluding text string). By default it uses a fast memory allocator, and the parser allocates memory compactly during parsing. RapidJSON is Unicode friendly. It supports UTF-8, UTF-16, UTF-32 (LE & BE), and their detection, validation and transcoding internally. For example, you can read a UTF-8 file and let RapidJSON transcode the JSON strings into UTF-16 in the DOM. It also supports surrogates and "\u0000" (null character). JSON(JavaScript Object Notation) is a light-weight data exchange format. RapidJSON should be in fully compliance with RFC4627/ECMA-404. -------------------------------------------------------------------------------- Update Information: Fix for CVE-2024-38517. -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 10 2024 Tom Hughes - 1.1.0-41 - Add patch for CVE-2024-38517 aka RHBZ#2296979 * Sun Feb 25 2024 Richard W.M. Jones - 1.1.0-28 - Bump andrebuild package (for riscv64) * Fri Jan 26 2024 Fedora Release Engineering - 1.1.0-27 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Mon Jan 22 2024 Fedora Release Engineering - 1.1.0-26 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Thu Jan 18 2024 Tom Hughes - 1.1.0-25 - Add upstream patches for improved gcc 14 and C++20 support * Fri Jan 5 2024 Honza Horak - 1.1.0-24 - SPDX migration - Add BSD license that is used by stdint.h and inttypes.h -------------------------------------------------------------------------------- References: [ 1 ] Bug #2296979 - CVE-2024-38517 rapidjson: privilege escalation via integer underflow in GenericReader::ParseNumber() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2296979 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a3c1b2629e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fix for CVE-2024-38517.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-fb1e912d0e 2024-07-19 01:45:23.518882 -------------------------------------------------------------------------------- Name : rapidjson Product : Fedora 40 Version : 1.1.0 Release : 41.fc40 URL : http://rapidjson.org/ Summary : Fast JSON parser and generator for C++ Description : RapidJSON is a fast JSON parser and generator for C++. It was inspired by RapidXml. RapidJSON is small but complete. It supports both SAX and DOM style API. The SAX parser is only a half thousand lines of code. RapidJSON is fast. Its performance can be comparable to strlen(). It also optionally supports SSE2/SSE4.1 for acceleration. RapidJSON is self-contained. It does not depend on external libraries such as BOOST. It even does not depend on STL. RapidJSON is memory friendly. Each JSON value occupies exactly 16/20 bytes for most 32/64-bit machines (excluding text string). By default it uses a fast memory allocator, and the parser allocates memory compactly during parsing. RapidJSON is Unicode friendly. It supports UTF-8, UTF-16, UTF-32 (LE & BE), and their detection, validation and transcoding internally. For example, you can read a UTF-8 file and let RapidJSON transcode the JSON strings into UTF-16 in the DOM. It also supports surrogates and "\u0000" (null character). JSON(JavaScript Object Notation) is a light-weight data exchange format. RapidJSON should be in fully compliance with RFC4627/ECMA-404. -------------------------------------------------------------------------------- Update Information: Fix for CVE-2024-38517. -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 10 2024 Tom Hughes - 1.1.0-41 - Add patch for CVE-2024-38517 aka RHBZ#2296979 * Sun Feb 25 2024 Richard W.M. Jones - 1.1.0-28 - Bump andrebuild package (for riscv64) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2296979 - CVE-2024-38517 rapidjson: privilege escalation via integer underflow in GenericReader::ParseNumber() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2296979 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-fb1e912d0e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.