FS#66678 - [json-c] [Security] integer overflow and out-of-bounds write (CVE-2020-12762)
Attached to Project:
Arch Linux
Opened by Morten Linderud (Foxboron) - Saturday, 16 May 2020, 18:57 GMT
Last edited by Levente Polyak (anthraxx) - Sunday, 20 December 2020, 02:44 GMT
Opened by Morten Linderud (Foxboron) - Saturday, 16 May 2020, 18:57 GMT
Last edited by Levente Polyak (anthraxx) - Sunday, 20 December 2020, 02:44 GMT
|
Details
Summary
======= The package json-c is vulnerable to integer overflow and out-of-bounds write via CVE-2020-12762. Guidance ======== Please apply the given patches from upstream. References ========== https://security.archlinux.org/AVG-1160 |
This task depends upon
Closed by Levente Polyak (anthraxx)
Sunday, 20 December 2020, 02:44 GMT
Reason for closing: Fixed
Additional comments about closing: 0.15-1
Sunday, 20 December 2020, 02:44 GMT
Reason for closing: Fixed
Additional comments about closing: 0.15-1
Ubuntu released patched version (although 0.13) as seen there: http://changelogs.ubuntu.com/changelogs/pool/main/j/json-c/json-c_0.13.1+dfsg-7ubuntu0.3/changelog
Redhat listed patches here: https://bugzilla.redhat.com/show_bug.cgi?id=1835253#c11 (did not verified it)