[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 3461-1] libfastjson security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3461-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                    Thorsten Alteholz
June 20, 2023                                 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : libfastjson
Version        : 0.99.8-2+deb10u1
CVE ID         : CVE-2020-12762


An issue has been found in libfastjson, a fast json library for C.
Due to missing checks, out-of-bounds write might happen when parsing large JSON files.


For Debian 10 buster, this problem has been fixed in version
0.99.8-2+deb10u1.

We recommend that you upgrade your libfastjson packages.

For the detailed security status of libfastjson please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libfastjson

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmSSFplfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7
WEeJ3hAAh1Pu4eQmOeWxoNFjLS0LEY6tK4sgECfqGov4rZkdM7pGf0IJaUlFYQQT
wq1+xEb6qkXw4kR6loJlc4J89ULFaW67nqcxioDPXtZQ8Zs6EStPfbvA9h0MiKMr
ah3cjnSVHMljKiWIOmY5GApFyW1C+60XcW8udiaL9qNnYd4MN3I7l3Spih6r/3Pk
Lg7i7WGTmuvzYvxZfa96JMCrcM+ofUq6d2YwlBMM2/QTQmK2hXjRnD4+2zOH61d0
b9kXrjrBlGjUQUUfRK4mt2ga4N//U8tdO2Xkg25+XZm4dtOR86+zV4iwBPVFn6zY
QTWF+rkTrWwczKRSr9tITJrlhvfnd8VqUNw6ZC/b4aWmI2a1Rkgtf0fU3S07pdqB
yumPl8etFzOAX/aYNVqTUJgb71F7bGdxLL9keR/RUYHBzIi6xOwGgRbN/NJWxPpn
71ZkDmjXMp08YbMfZWwcprF4BrB7a9ucqWS32OWnOxxxBM8wJUhpTXcjdsLDUKt8
kc3wJ5EX0woSWNfL9lEcAsmM2NM0axtx27mR2R+/w0IynX2AIPwx0vn1gzuSrmss
t/g9CV0Gc/YXl6KB6k76+bS0lv+WKycUbg/m5d4wO6WKwTma/JyasIEW2UqZ9RD3
qkEDLhQajEZKXCw9cqQwYoyltr39x0oW2oOggWcdGkVKDVKmjCw=
=FZ2p
-----END PGP SIGNATURE-----


Reply to: