CVE-2013-6401
Publication date 21 March 2014
Last updated 24 July 2024
Ubuntu priority
Jansson, possibly 2.4 and earlier, does not restrict the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted JSON document.
From the Ubuntu Security Team
Florian Weimer discovered that Jansson incorrectly handled hash collisions predictability. An attacker could possibly use this issue to cause a denial of service.
Status
Package | Ubuntu Release | Status |
---|---|---|
jansson | 18.04 LTS bionic |
Not affected
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Fixed 2.5-2ubuntu0.1
|
|