Ubuntu Security Update USN-6758-1: JSON5 vulnerability

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,873
Reaction score
74
Credits
-1,257
It was discovered that the JSON5 parse method incorrectly handled the parsing of keys named \\_proto\\_. An attacker could possibly use this issue to pollute the prototype of the returned object, setting arbitrary or unexpected keys, and cause a denial of service, allow unintended access to network services or have other unspecified impact, depending on the application's use of the module.

Continue reading...
 


Follow Linux.org

Staff online

Members online


Top