CVE-2016-4303
26.09.2016, 14:59
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.
Vendor | Product | Version |
---|---|---|
es | iperf3 | 3.0 ≤ 𝑥 < 3.0.12 |
es | iperf3 | 3.1 ≤ 𝑥 < 3.1.3 |
opensuse | leap | 42.1 |
opensuse | opensuse | 13.2 |
debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
iperf |
| ||||||||||||||||||||||||||||||||
iperf3 |
|