The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Json-c | Json-c | * | 0.12-20140410 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | json-c-0:0.11-4.el7_0 | * |
Json-c | Ubuntu | lucid | * |
Json-c | Ubuntu | precise | * |
Json-c | Ubuntu | quantal | * |
Json-c | Ubuntu | saucy | * |
Json-c | Ubuntu | trusty | * |
Json-c | Ubuntu | upstream | * |