CVE-2013-6371: Fedoraproject Fedora

Medium severity, CVSS 5.0. EPSS: 3.1% chance of exploitation in the next 30 days.

The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions.

Affected products

  • Fedoraproject Fedora: version 20 only
  • JSON-C JSON-C: before 0.12-20140410 (fixed in 0.12-20140410)

Published 2014-04-22. Last modified 2026-06-17.