Executive brief
UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.
Affected products
- PyPI ujson
Junglewise Threat Intelligence
CVE-2021-45958 · Severity: low · CVSS 3.1 · Published 2022-01-01
Technologies: ujson (PyPI). Vendors: PyPI.
UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.