Bug 58643 - libjson-xs-perl: Multiple issues (5.2)
Summary: libjson-xs-perl: Multiple issues (5.2)
Status: CLOSED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: Security updates
Version: UCS 5.2
Hardware: All Linux
: P3 normal
Target Milestone: UCS 5.2-3-errata
Assignee: Quality Assurance
QA Contact: Christian Castens
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2025-09-15 10:50 CEST by Quality Assurance
Modified: 2025-09-17 14:09 CEST (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID:
Max CVSS v3 score: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) NVD


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2025-09-15 10:50:18 CEST
New Debian libjson-xs-perl 4.040-1~deb12u1 fixes:
This update addresses the following issue:
4.040-1~deb12u1 (Mon, 08 Sep 2025 22:30:23 +0200)
* Rebuild for bookworm-security
4.040-1 (Mon, 08 Sep 2025 20:19:17 +0200)
* Team upload.
* Import upstream version 4.040. - Fix json_atof_scan1 overflows  (CVE-2025-40928)
* Drop initial patch for CVE-2025-40928 in favour of upstream changes
* Drop patches applied upstream
4.030-3 (Mon, 08 Sep 2025 17:34:12 +0200)
* Fix json_atof_scan1 overflows (CVE-2025-40928)
Comment 1 Quality Assurance univentionstaff 2025-09-15 11:00:14 CEST
--- mirror/ftp/pool/main/libj/libjson-xs-perl/libjson-xs-perl_4.030-2.dsc
+++ apt/ucs_5.2-0-errata5.2-3/source/libjson-xs-perl_4.040-1~deb12u1.dsc
@@ -1,3 +1,20 @@
+4.040-1~deb12u1 [Mon, 08 Sep 2025 22:30:23 +0200] Salvatore Bonaccorso <carnil@debian.org>:
+
+  * Rebuild for bookworm-security
+
+4.040-1 [Mon, 08 Sep 2025 20:19:17 +0200] Salvatore Bonaccorso <carnil@debian.org>:
+
+  * Team upload.
+  * Import upstream version 4.040.
+    - Fix json_atof_scan1 overflows (CVE-2025-40928)
+  * Drop initial patch for CVE-2025-40928 in favour of upstream changes
+  * Drop patches applied upstream
+
+4.030-3 [Mon, 08 Sep 2025 17:34:12 +0200] Salvatore Bonaccorso <carnil@debian.org>:
+
+  * Team upload.
+  * Fix json_atof_scan1 overflows (CVE-2025-40928)
+
 4.030-2 [Sun, 28 Aug 2022 14:33:48 +0100] Jelmer Vernooij <jelmer@debian.org>:
 
   [ Debian Janitor ]

<http://piuparts.knut.univention.de/5.2-3/#4646809253371733373>
Comment 2 Christian Castens univentionstaff 2025-09-17 13:25:23 CEST
OK: bug
OK: yaml
OK: announce_errata
OK: patch
~OK: piuparts
    manual test OK

[5.2-3] 8e4f13e827 Bug #58643: libjson-xs-perl 4.040-1~deb12u1
 doc/errata/staging/libjson-xs-perl.yaml | 13 +++++++++++++
 1 file changed, 13 insertions(+)
Comment 3 Christian Castens univentionstaff 2025-09-17 14:09:19 CEST
<https://errata.software-univention.de/#/?erratum=5.2x200>