oss-sec mailing list archives

CVE Request: Jansson: stack exhaustion parsing a JSON file


From: Gustavo Grieco <gustavo.grieco () gmail com>
Date: Sun, 1 May 2016 22:10:11 +0200

Hi,

A crash caused by stack exhaustion parsing a JSON was found. It affects, at
least version 2.5 as well as the last git revision. Technical details and a
reproducer are available here:

https://github.com/akheron/jansson/issues/282

This crash was found by QuickFuzz working with Radamsa (again caused the
extreme mutation). It was manually minimized later.

Regards,
Gustavo.

Current thread: