CVE-2013-6401
Published Mar 21, 2014
Last updated 10 years ago
Overview
- Description
- Jansson, possibly 2.4 and earlier, does not restrict the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted JSON document.
- Source
- secalert@redhat.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- CWE-310
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:jansson_project:jansson:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "022888A4-6012-4564-B3F4-BDA2DA4CE84F", "versionEndIncluding": "2.4" }, { "criteria": "cpe:2.3:a:jansson_project:jansson:2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "45406101-3C11-4CEE-83FA-8831CEFCEA23" }, { "criteria": "cpe:2.3:a:jansson_project:jansson:2.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6184FE2F-1772-4F59-964C-94EE19459FCE" }, { "criteria": "cpe:2.3:a:jansson_project:jansson:2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F36E0035-1F30-4D27-B73E-C46D5156C069" }, { "criteria": "cpe:2.3:a:jansson_project:jansson:2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "72C31418-B802-4598-9FAD-67C8A287121C" }, { "criteria": "cpe:2.3:a:jansson_project:jansson:2.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D29BEA76-DCAF-46F4-9520-D983CA9EF8DF" }, { "criteria": "cpe:2.3:a:jansson_project:jansson:2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A389815-0428-4267-AAFC-2B57AAA314CD" }, { "criteria": "cpe:2.3:a:jansson_project:jansson:2.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A3AFCF62-51BD-467D-B614-2F3198EB310A" } ], "operator": "OR" } ] } ]