Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora: 2016-cc7f19cb5b Moderate: Jansson Stack Exhaustion Fix

Update to Jansson 2.9. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-cc7f19cb5b 2016-09-27 21:44:48.198692 -------------------------------------------------------------------------------- Name : jansson Product : Fedora 23 Version : 2.9 Release : 1.fc23 URL : https://github.com/akheron/jansson Summary : C library for encoding, decoding and manipulating JSON data Description : Small library for parsing and writing JSON documents. -------------------------------------------------------------------------------- Update Information: Update to Jansson 2.9 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1332202 - CVE-2016-4425 jansson: stack exhaustion parsing a JSON file [epel-6] https://bugzilla.redhat.com/show_bug.cgi?id=1332202 [ 2 ] Bug #1332201 - CVE-2016-4425 jansson: stack exhaustion parsing a JSON file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1332201 [ 3 ] Bug #1375710 - Rebase jansson + patch https://bugzilla.redhat.com/show_bug.cgi?id=1375710 [ 4 ] Bug #1150479 - jansson-2.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=1150479 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update jansson' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Upgrade to Jansson 2.9 in Fedora 23,fixing security vulnerabilities concerning stack overflow issues.. Fedora Update, Jansson Fix, Stack Issues, JSON Security. . LinuxSecurity.com Team

Calendar 2 Sep 28, 2016 Fedora
89

Fedora 24 FEDORA-2016-59fda81436 Critical: Jansson Stack Exhaustion

Update to Jansson 2.9. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-59fda81436 2016-09-27 21:45:57.004118 -------------------------------------------------------------------------------- Name : jansson Product : Fedora 24 Version : 2.9 Release : 1.fc24 URL : https://github.com/akheron/jansson Summary : C library for encoding, decoding and manipulating JSON data Description : Small library for parsing and writing JSON documents. -------------------------------------------------------------------------------- Update Information: Update to Jansson 2.9 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1332202 - CVE-2016-4425 jansson: stack exhaustion parsing a JSON file [epel-6] https://bugzilla.redhat.com/show_bug.cgi?id=1332202 [ 2 ] Bug #1332201 - CVE-2016-4425 jansson: stack exhaustion parsing a JSON file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1332201 [ 3 ] Bug #1375710 - Rebase jansson + patch https://bugzilla.redhat.com/show_bug.cgi?id=1375710 [ 4 ] Bug #1150479 - jansson-2.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=1150479 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update jansson' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest upgrade of Jansson 2.9 forFedora 24 resolves urgent stack overflow vulnerabilities; apply this update via 'yum update'.. Jansson Update, Fedora 24 Security, JSON Library Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 28, 2016 Critical Fedora
89

Fedora 26: FEDORA-2017-83a6b82ee2 Critical: Jansson Memory Leak

Update to Jansson 2.9. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-72a6c79ee1 2016-09-27 00:29:22.122563 -------------------------------------------------------------------------------- Name : jansson Product : Fedora 25 Version : 2.9 Release : 1.fc25 URL : https://github.com/akheron/jansson Summary : C library for encoding, decoding and manipulating JSON data Description : Small library for parsing and writing JSON documents. -------------------------------------------------------------------------------- Update Information: Update to Jansson 2.9 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1332202 - CVE-2016-4425 jansson: stack exhaustion parsing a JSON file [epel-6] https://bugzilla.redhat.com/show_bug.cgi?id=1332202 [ 2 ] Bug #1332201 - CVE-2016-4425 jansson: stack exhaustion parsing a JSON file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1332201 [ 3 ] Bug #1375710 - Rebase jansson + patch https://bugzilla.redhat.com/show_bug.cgi?id=1375710 [ 4 ] Bug #1150479 - jansson-2.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=1150479 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update jansson' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. .-------------------------------------------------------------------------------- Fedora Update Notif. update, jansson, ------------------------------------------------------------------------------. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 27, 2016 Critical Fedora
198

Arch Linux: ASA-201609-15 Low: Jansson Denial Of Service

The package jansson before version 2.8-1 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-201609-15 ========================================= Severity: Low Date : 2016-09-17 CVE-ID : CVE-2016-4425 Package : jansson Type : denial of service Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The package jansson before version 2.8-1 is vulnerable to denial of service. Resolution ========= Upgrade to 2.8-1. # pacman -Syu "jansson> =2.8-1" The problem has been fixed upstream in version 2.8. Workaround ========= None. Description ========== A stack-exhaustion vulnerability has been found in jansson, causing a crash while parsing a crafted JSON document. Impact ===== A remote attacker might cause a crash by submitting a specially crafted JSON file to an application using jansson, leading to denial of service. References ========= https://marc.info/;m=146219323703639&w=2 https://github.com/akheron/jansson/issues/282 https://access.redhat.com/security/cve/CVE-2016-4425 . The Debian Security Advisory DSA-2021-12 highlights a medium severity vulnerability affecting the libyaml library.. Arch Linux,Jansson,Denial of Service,Low Severity,Software Update. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Sep 17, 2016 Low ArchLinux
87

Debian 8: DSA-3577-1 Moderate: Jansson Denial Of Service Issue

Gustavo Grieco discovered that jansson, a C library for encoding, decoding and manipulating JSON data, did not limit the recursion depth when parsing JSON arrays and objects. This could allow remote attackers to cause a denial of service (crash) via stack exhaustion, using crafted . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3577-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Alessandro Ghedini May 14, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : jansson CVE ID : CVE-2016-4425 Debian Bug : 823238 Gustavo Grieco discovered that jansson, a C library for encoding, decoding and manipulating JSON data, did not limit the recursion depth when parsing JSON arrays and objects. This could allow remote attackersto cause a denial of service (crash) via stack exhaustion, using crafted JSON data. For the stable distribution (jessie), this problem has been fixed in version 2.7-1+deb8u1. For the unstable distribution (sid), this problem has been fixed in version 2.7-5. We recommend that you upgrade your jansson packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A crucial Jansson library update for Debian has been released to fix vulnerabilities linked to unbounded recursion depth, enhancing application stability and security. jansson, denial of service, json library, debian security, stack exhaustion. . LinuxSecurity.com Team

Calendar 2 May 14, 2016 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here