Tencent RapidJSON is vulnerable to privilege escalation due to an integer underflow in the GenericReader::ParseNumber()
function of include/rapidjson/reader.h
when parsing JSON text from a stream. An attacker needs to send the victim a crafted file which needs to be opened; this triggers the integer underflow vulnerability (when the file is parsed), leading to elevation of privilege.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.12~git20141031-3ubuntu0.1~esm1", "binary_name": "rapidjson-dev" }, { "binary_version": "0.12~git20141031-3ubuntu0.1~esm1", "binary_name": "rapidjson-doc" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.1.0+dfsg2-3ubuntu0.1~esm1", "binary_name": "rapidjson-dev" }, { "binary_version": "1.1.0+dfsg2-3ubuntu0.1~esm1", "binary_name": "rapidjson-doc" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.1.0+dfsg2-5ubuntu1+esm1", "binary_name": "rapidjson-dev" }, { "binary_version": "1.1.0+dfsg2-5ubuntu1+esm1", "binary_name": "rapidjson-doc" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.1.0+dfsg2-7ubuntu0.1~esm1", "binary_name": "rapidjson-dev" }, { "binary_version": "1.1.0+dfsg2-7ubuntu0.1~esm1", "binary_name": "rapidjson-doc" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.1.0+dfsg2-7.2ubuntu0.1~esm1", "binary_name": "rapidjson-dev" }, { "binary_version": "1.1.0+dfsg2-7.2ubuntu0.1~esm1", "binary_name": "rapidjson-doc" } ] }