CVE-2016-4303: Debian Linux

Critical severity, CVSS 9.8. EPSS: 7% chance of exploitation in the next 30 days.

The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Es IPERF3: from 3.0, before 3.0.12 (fixed in 3.0.12); from 3.1, before 3.1.3 (fixed in 3.1.3)
  • Novell Suse Package Hub For Suse Linux Enterprise: version 12 only
  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 13.2 only

Published 2016-09-26. Last modified 2026-06-17.