CVE-2016-4303: Debian Linux
Critical severity, CVSS 9.8. EPSS: 7% chance of exploitation in the next 30 days.
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.
Affected products
- Debian Debian Linux: version 8.0 only
- Es IPERF3: from 3.0, before 3.0.12 (fixed in 3.0.12); from 3.1, before 3.1.3 (fixed in 3.1.3)
- Novell Suse Package Hub For Suse Linux Enterprise: version 12 only
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.2 only
Published 2016-09-26. Last modified 2026-06-17.