Description
Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
Problem types
CWE-122 Heap-based Buffer Overflow
Product status
Any version before 4.40
Credits
Michael Hudak of rasotec
References
metacpan.org/release/RURBAN/Cpanel-JSON-XS-4.39/source/XS.xs
metacpan.org/release/RURBAN/Cpanel-JSON-XS-4.40/changes
github.com/...378236219eaa35742c3962ecbdee364903b0a1f2.patch