CVE-2013-6401

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
21/03/2014
Last modified:
12/04/2025

Description

Jansson, possibly 2.4 and earlier, does not restrict the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted JSON document.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jansson_project:jansson:*:*:*:*:*:*:*:* 2.4 (including)
cpe:2.3:a:jansson_project:jansson:2.0:*:*:*:*:*:*:*
cpe:2.3:a:jansson_project:jansson:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:jansson_project:jansson:2.1:*:*:*:*:*:*:*
cpe:2.3:a:jansson_project:jansson:2.2:*:*:*:*:*:*:*
cpe:2.3:a:jansson_project:jansson:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:jansson_project:jansson:2.3:*:*:*:*:*:*:*
cpe:2.3:a:jansson_project:jansson:2.3.1:*:*:*:*:*:*:*