MGASA-2016-0198

Source
https://advisories.mageia.org/MGASA-2016-0198.html
Import Source
https://advisories.mageia.org/MGASA-2016-0198.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2016-0198
Related
Published
2016-05-21T22:11:24Z
Modified
2016-05-21T22:03:12Z
Summary
Updated jansson packages fix CVE-2016-4425
Details

Updated jansson packages fix security vulnerability:

Gustavo Grieco discovered that jansson did not limit the recursion depth when parsing JSON arrays and objects. This could allow remote attackers to cause a denial of service (crash) via stack exhaustion, using crafted JSON data (CVE-2016-4425).

References
Credits

Affected packages

Mageia:5 / jansson

Package

Name
jansson
Purl
pkg:rpm/mageia/jansson?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4-4.1.mga5

Ecosystem specific

{
    "section": "core"
}