VDB

ALPINE-CVE-2020-12762

ALPINE-CVE-2020-12762 PUBLISHED CVSS 7.800000190734863 HIGH

json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.19json-c0.14-r0, 0.12.1-r1, 0.12.1-r0
Alpine:v3.22json-c0.12.1-r0, 0.12.1-r1, 0.12.1-r0
Alpine:v3.17libfastjson0, 0.99.9-r0, 0.99.8-r2
Alpine:v3.21json-c0.12-r0, 0.12-r1, 0.12.1-r2
Alpine:v3.12json-c0.12.1-r1, 0, 0.11-r0
Alpine:v3.10json-c0.12.1-r2, 0.10-r0, 0.12.1-r2
Alpine:v3.11json-c0.12-r0, 0.13.1-r0, 0.12.1-r3
Alpine:v3.15libfastjson0.99.9-r0, 0.99.8-r2, 0.99.8-r1
Alpine:v3.20libfastjson0.99.9-r0, 0, 0.99.2-r0
Alpine:v3.23libfastjson0.99.7-r0, 0.99.2-r0, 0.99.2-r0
Alpine:v3.22libfastjson0.99.8-r1, 0.99.9-r1, 0.99.8-r2
Alpine:v3.9json-c0.12.1-r1, 0.12.1-r0, 0.12-r1
Alpine:v3.16json-c0.10-r0, 0, 0.11-r0
Alpine:v3.23json-c0, 0.14-r0, 0.13.1-r0
Alpine:v3.20json-c0.12.1-r1, 0.14-r0, 0.13.1-r0
Alpine:v3.14json-c0.12-r1, 0.10-r0, 0.11-r0
Alpine:v3.18libfastjson0.99.9-r1, 0.99.9-r0, 0.99.8-r2
Alpine:v3.13json-c0.10-r0, 0, 0.12-r1
Alpine:v3.16libfastjson0.99.4-r0, 0.99.2-r0, 0.99.4-r0
Alpine:v3.21libfastjson0, 0.99.2-r0, 0.99.4-r0

…and 4 more

Timeline

  • May 9, 2020 CVE Published
  • Dec 3, 2025 CVE Updated
  • Apr 30, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›