Bug 1203515 (CVE-2022-40149) - VUL-0: CVE-2022-40149: jettison: denial of service via user-supplied XML or JSON data
Summary: VUL-0: CVE-2022-40149: jettison: denial of service via user-supplied XML or J...
Status: RESOLVED FIXED
Alias: CVE-2022-40149
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/342794/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-09-19 09:48 UTC by Carlos López
Modified: 2024-04-19 14:12 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carlos López 2022-09-19 09:48:31 UTC
CVE-2022-40149

Those using Jettison to parse untrusted XML or JSON data may be vulnerable to
Denial of Service attacks (DOS). If the parser is running on user supplied
input, an attacker may supply content that causes the parser to crash by
stackoverflow. This effect may support a denial of service attack.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-40149
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=46538
https://github.com/jettison-json/jettison/issues/45
https://www.cve.org/CVERecord?id=CVE-2022-40149
Comment 1 Carlos López 2022-09-19 09:51:22 UTC
No public details yet
Comment 2 Carlos López 2022-10-05 08:09:08 UTC
Details open now:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=46538
Comment 3 Carlos López 2022-10-05 08:17:31 UTC
The fix is this one:
https://github.com/jettison-json/jettison/commit/395f8625bcf688743872c8e7f59360d372e77811

We would need the fix in:
- SUSE:SLE-15-SP2:Update
- openSUSE:Backports:SLE-15-SP3
- openSUSE:Factory
Comment 6 Fridrich Strba 2024-03-04 12:14:37 UTC
Time to close this one.
Comment 7 Robert Frohl 2024-04-19 14:12:25 UTC
done