MGASA-2022-0270

Source
https://advisories.mageia.org/MGASA-2022-0270.html
Import Source
https://advisories.mageia.org/MGASA-2022-0270.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2022-0270
Related
Published
2022-07-29T20:53:30Z
Modified
2022-07-29T20:02:35Z
Summary
Updated python-ujson packages fix security vulnerability
Details

Add support for arbitrary size integers. Replace 'wchart' string decoding implementation with a 'uint32t'-based one; fix handling of surrogates on decoding (CVE-2022-31116) Potential double free of buffer during string decoding - Fix memory leak on encoding errors when the buffer was resized - Integer parsing: always detect overflows - Fix handling of surrogates on encoding (CVE-2022-31117)

References
Credits

Affected packages

Mageia:8 / python-ujson

Package

Name
python-ujson
Purl
pkg:rpm/mageia/python-ujson?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.0-1.mga8

Ecosystem specific

{
    "section": "core"
}