Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Ubuntu 22.04 LTS: USN-6705-1 Critical: JSON Processing Vulnerability

ubuntu
Calendar Grey March 12, 2024
Dist Ubuntu Esm H88
Explore the recent Gson flaw impacting various Ubuntu releases and learn effective strategies to curb denial of service threats through timely updates.
Gson could be made to crash if it opened a specially crafted file.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Gson could be made to crash if it opened a specially crafted file. Software Description: - libgoogle-gson-java: A Java serialization/deserialization library to convert Java Objects into JSON and back Details: It was discovered that Gson incorrectly handled deserialization of untrusted input data. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service.

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: libgoogle-gson-java 2.8.8-1ubuntu0.1 Ubuntu 20.04 LTS: libgoogle-gson-java 2.8.5-3+deb10u1build0.20.04.1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): libgoogle-gson-java 2.8.5-3~18.04.1~esm1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): libgoogle-gson-java 2.4-1ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes.

References

CVE-2022-25647

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-6692-1

Package Information

https://launchpad.net/ubuntu/+source/libgoogle-gson-java/2.8.8-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libgoogle-gson-java/2.8.5-3+deb10u1build0.20.04.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here