CVE-2020-12762: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 1.9% chance of exploitation in the next 30 days.
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 19.10 only; version 20.04 only
- Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
- Fedoraproject Fedora: version 30 only; version 31 only; version 32 only
- JSON-C JSON-C: before 0.15-20200726 (fixed in 0.15-20200726)
- Siemens Sinec Ins: affected versions not specified; version 1.0 only
Published 2020-05-09. Last modified 2026-06-17.