Bug 1203516 - (CVE-2022-40150) VUL-0: CVE-2022-40150: jettison: denial of service via user-supplied XML or JSON data
(CVE-2022-40150)
VUL-0: CVE-2022-40150: jettison: denial of service via user-supplied XML or J...
Status: NEW
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Fridrich Strba
Security Team bot
https://smash.suse.de/issue/342793/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-09-19 09:49 UTC by Carlos López
Modified: 2022-10-05 09:19 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carlos López 2022-09-19 09:49:29 UTC
CVE-2022-40150

Those using Jettison to parse untrusted XML or JSON data may be vulnerable to
Denial of Service attacks (DOS). If the parser is running on user supplied
input, an attacker may supply content that causes the parser to crash by Out of
memory. This effect may support a denial of service attack.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-40150
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=46549
https://www.cve.org/CVERecord?id=CVE-2022-40150
https://github.com/jettison-json/jettison/issues/45
Comment 1 Carlos López 2022-09-19 09:51:25 UTC
No public details yet
Comment 2 Carlos López 2022-10-05 08:20:04 UTC
Fix is this one:
https://github.com/jettison-json/jettison/commit/1268b7558bad9b989687009a094466b64d4da533

We would need the fix in:
- SUSE:SLE-15-SP2:Update
- openSUSE:Backports:SLE-15-SP3
- openSUSE:Factory