CVE-2021-32292 is a critical stack-buffer-overflow vulnerability (CWE-787) in the json-c library, specifically within the json_parse sample program's parseit function, affecting versions from 20200420 to 0.15-20200726, including NetApp Active IQ Unified Manager. With a CVSS score of 9.8, it allows unauthenticated remote attackers to achieve high impact on confidentiality, integrity, and availability with low attack complexity. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* | ||
0.15-20200726CPE matchmatch criteria | cpe:2.3:a:json-c:json-c:0.15-20200726:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
json-c: stack-buffer-overflow in parseit() in json_parse.c
Aug 22, 2023An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.
Aug 8, 2023