Univention Bugzilla – Bug 51755
json-c: Multiple issues (4.4)
Last modified: 2020-08-05 15:15:35 CEST
New Debian json-c 0.12.1-1.1+deb9u1 fixes: This update addresses the following issue: * integer overflow and out-of-bounds write via a large JSON file (CVE-2020-12762)
--- mirror/ftp/4.3/unmaintained/4.3-0/source/json-c_0.12.1-1.1.dsc +++ apt/ucs_4.4-0-errata4.4-5/source/json-c_0.12.1-1.1+deb9u1.dsc @@ -1,3 +1,9 @@ +0.12.1-1.1+deb9u1 [Thu, 30 Jul 2020 12:58:32 +0200] Emilio Pozuelo Monfort <pochu@debian.org>: + + * Non-maintainer upload by the LTS Team. + * CVE-2020-12762: integer overflow leading to buffer overwrite when reading + specially crafted large files. + 0.12.1-1.1 [Mon, 14 Nov 2016 11:33:17 +0100] Martin Pitt <mpitt@debian.org>: * Non-maintainer upload. <http://10.200.17.11/4.4-5/#3787895522424248096>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-5] 867104a4e7 Bug #51755: json-c 0.12.1-1.1+deb9u1 doc/errata/staging/json-c.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x690>