USN-7125-1: RapidJSON vulnerability
25 November 2024
RapidJSON could be made to crash or run programs as your login if it opened a specially crafted file.
Releases
Packages
- rapidjson - A fast JSON parser/generator for C++
Details
It was discovered that RapidJSON incorrectly parsed numbers written in
scientific notation, leading to an integer underflow. An attacker could
possibly use this issue to cause a denial of service, or execute arbitrary
code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10
Ubuntu 24.04
-
rapidjson-dev
-
1.1.0+dfsg2-7.2ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 22.04
-
rapidjson-dev
-
1.1.0+dfsg2-7ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 20.04
-
rapidjson-dev
-
1.1.0+dfsg2-5ubuntu1+esm1
Available with Ubuntu Pro
Ubuntu 18.04
-
rapidjson-dev
-
1.1.0+dfsg2-3ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
rapidjson-dev
-
0.12~git20141031-3ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.