Bug#960326: json-c: CVE-2020-12762

2020-06-05 Thread Armand Grillet
Hi, A fix has landed in json-c-0.12 (which is the upstream used for json-c in Debian Buster): https://github.com/json-c/json-c/commit/f2b7d0b5cbd0eccf4fb3c1851ec0864952be1057 I do not know how to get this fix in Debian's json-c repository https://salsa.debian.org/debian/json-c as there is a branc

Bug#960326: json-c: CVE-2020-12762

2020-05-15 Thread Salvatore Bonaccorso
Hi, On Fri, May 15, 2020 at 10:19:42PM +0200, Salvatore Bonaccorso wrote: > Hi, > > On Mon, May 11, 2020 at 09:55:12PM +0200, Salvatore Bonaccorso wrote: > > Source: json-c > > Version: 0.13.1+dfsg-7 > > Severity: important > > Tags: security upstream > > Forwarded: https://github.com/json-c/json

Bug#960326: json-c: CVE-2020-12762

2020-05-15 Thread Salvatore Bonaccorso
Hi, On Mon, May 11, 2020 at 09:55:12PM +0200, Salvatore Bonaccorso wrote: > Source: json-c > Version: 0.13.1+dfsg-7 > Severity: important > Tags: security upstream > Forwarded: https://github.com/json-c/json-c/pull/592 > > Hi, > > The following vulnerability was published for json-c. > > CVE-20

Bug#960326: json-c: CVE-2020-12762

2020-05-11 Thread Salvatore Bonaccorso
Source: json-c Version: 0.13.1+dfsg-7 Severity: important Tags: security upstream Forwarded: https://github.com/json-c/json-c/pull/592 Hi, The following vulnerability was published for json-c. CVE-2020-12762[0]: | json-c through 0.14 has an integer overflow and out-of-bounds write | via a large