DescriptionJansson, possibly 2.4 and earlier, does not restrict the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted JSON document.
NVD CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Novell/SUSE informationNovell Bugzilla entry: 863301 SUSE Security Advisories:
- openSUSE-SU-2014:0394-1, published Wed, 19 Mar 2014 11:04:13 +0100 (CET)
List of released packages
|Product(s)||Fixed package version(s)||References|
|SUSE Studio Onsite 1.3|| ||Builds|
SAT Patch Nr: 9005