Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Debian 8: DSA-3577-1 Moderate: Jansson Denial Of Service Issue

debian
Calendar Grey May 14, 2016
Scroller Debian
A crucial Jansson library update for Debian has been released to fix vulnerabilities linked to unbounded recursion depth, enhancing application stability and security
Gustavo Grieco discovered that jansson, a C library for encoding, decoding and manipulating JSON data, did not limit the recursion depth when parsing JSON arrays and objects

Summary

For the stable distribution (jessie), this problem has been fixed in
version 2.7-1+deb8u1.

For the unstable distribution (sid), this problem has been fixed in
version 2.7-5.

We recommend that you upgrade your jansson packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Package: jansson
CVE ID: CVE-2016-4425

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.