Ubuntu Security Update USN-6758-1: JSON5 vulnerability

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,873
Reaction score
74
Credits
-1,257
It was discovered that the JSON5 parse method incorrectly handled the parsing of keys named \\_proto\\_. An attacker could possibly use this issue to pollute the prototype of the returned object, setting arbitrary or unexpected keys, and cause a denial of service, allow unintended access to network services or have other unspecified impact, depending on the application's use of the module.

Continue reading...
 


Follow Linux.org

Members online


Top