JSON Denial of Service and Security Bypass Vulnerabilities
BID:57899
Info
JSON Denial of Service and Security Bypass Vulnerabilities
| Bugtraq ID: | 57899 |
| Class: | Unknown |
| CVE: |
CVE-2013-0269 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2013 12:00AM |
| Updated: | Apr 13 2015 09:15PM |
| Credit: | Thomas Hollstegge of Zweitag and Ben Murphy |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.10 i386 Ubuntu Ubuntu Linux 12.10 amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 SuSE WebYaST 1.3 SuSE WebYaST 1.2 SuSE SUSE Linux Enterprise Software Development Kit 11 SP2 SuSE Studio Standard Edition 1.2 SuSE Studio Onsite 1.3 SuSE Studio Onsite 1.2 SuSE Studio Extension for System z 1.2 SuSE Lifecycle Management Server 1.3 SuSE Cloud 1.0 Slackware Linux x86_64 -current Slackware Linux 14.0 x86_64 Slackware Linux 14.0 Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux -current Redhat Subscription Asset Manager 1.2 Redhat Subscription Asset Manager 1.1 Redhat OpenShift Enterprise 1.1.3 Redhat JBoss Fuse 6.0 Redhat Fuse ESB Enterprise 7.1.0 JSON JSON 1.7.6 JSON JSON 1.6.7 JSON JSON 1.5.4 Gentoo Linux Apple Mac OS X Server 2.2.2 Apple Mac OS X Server 2.2.1 Apple Mac OS X Server 2.1.1 Apple Mac OS X Server 2.1 Apple Mac OS X Server 2.0 |
| Not Vulnerable: |
Redhat Subscription Asset Manager 1.2.1 Redhat Fuse ESB Enterprise 7.1.0 Patch 1 JSON JSON 1.7.7 JSON JSON 1.6.8 JSON JSON 1.5.5 Apple Mac OS X Server 3.0 |
References
JSON Denial of Service and Security Bypass Vulnerabilities
References:
References:
- Denial of Service and Unsafe Object Creation Vulnerability in JSON [CVE-2013-026 (Aaron Patterson)
- JSON Homepage (JSON)
- Patch update for [CVE-2013-0269] (Aaron Patterson)
- Moderate: Subscription Asset Manager 1.2.1 update (Red Hat)
- RHSA-2013:0701-1: Moderate: ruby193-ruby, rubygem-json and rubygem-rdoc security (Red Hat)
- RHSA-2013:1028-1: Fuse ESB Enterprise 7.1.0 update (Red Hat)