RURBAN Cpanel::JSON::XS
cpe:2.3:a:rurban:cpanel::json::xs:*:*:*:*:perl:*:*
- < 4.40
An integer buffer overflow vulnerability has been identified in Cpanel::JSON::XS versions prior to 4.40 for Perl. This vulnerability occurs when the module parses crafted JSON, leading to a segmentation fault. The buffer overflow can be exploited to cause a denial-of-service condition or potentially other unspecified impacts.
Exploitation of this vulnerability causes a segmentation fault, leading to a denial-of-service condition.
The vulnerability can be reproduced by parsing JSON data that includes overlong numeric values. This can be done using the Cpanel::JSON::XS module in Perl, by crafting a JSON string that contains a number formatted to exceed the normal length, which will trigger the buffer overflow during parsing.
Users can upgrade to Cpanel::JSON::XS version 4.40 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.