The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Json-c | Json-c | * | 0.12-20140410 (excluding) |
| Red Hat Enterprise Linux 7 | RedHat | json-c-0:0.11-4.el7_0 | * |
| Json-c | Ubuntu | esm-infra-legacy/trusty | * |
| Json-c | Ubuntu | lucid | * |
| Json-c | Ubuntu | precise | * |
| Json-c | Ubuntu | quantal | * |
| Json-c | Ubuntu | saucy | * |
| Json-c | Ubuntu | trusty | * |
| Json-c | Ubuntu | trusty/esm | * |
| Json-c | Ubuntu | upstream | * |