Heap-Based Buffer Over-Read in cJSON Library by Dave Gamble
CVE-2023-53154
2.9LOW
What is CVE-2023-53154?
The cJSON library, specifically versions before 1.7.18, is susceptible to a heap-based buffer over-read when utilizing the parse_string function. This vulnerability arises when cJSON_ParseWithLength is executed with improperly formatted input, such as a JSON object lacking a trailing newline. As a result, this flaw can lead to unexpected data exposure and potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
cJSON 0 < 1.7.18
