OSV-2021-955 – ujson
Package
Manager: pip
Name: ujson
Vulnerable Version: =2.0.0 || =2.0.1 || =2.0.2 || =2.0.3 || =3.0.0 || =3.1.0 || =3.2.0 || =4.0.0 || =4.0.1 || =4.0.2 || =4.1.0 || =4.2.0 || =4.3.0 || =5.0.0 || =5.1.0 || =1.34 || =1.35 || >=0c52200eb4e2d97e548a765d5f089858c41967b0 <f6860f1f3d8d4e92b9be0e5815355a8976c6e75b
Severity
Level: Low
CVSS v3.1: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
EPSS: N/A pctlN/A
Details
Stack-buffer-overflow in Buffer_AppendIndentUnchecked OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=36009 ``` Crash type: Stack-buffer-overflow WRITE 1 Crash state: Buffer_AppendIndentUnchecked encode encode ```
Metadata
Created: 2021-07-11T00:01:05.153778Z
Modified: 2022-05-19T00:45:08.957102Z
Source: https://osv-vulnerabilities
CWE IDs: N/A
Alternative ID: N/A
Finding: F316
Auto approve: 1