Jansson 2. 7 and earlier allows context-dependent attackers to cause a denial of service (deep recursion, stack consumption, and crash) via crafted json data. The table below lists information on source … Debianization for jansson.

Jansson, possibly 2. 4 and earlier, does not restrict the ability to tr I reviewed the diff between 2. 14 in kinetic and this upload (just changelog), and i carefully reviewed the 2. 13 + ubuntu changes to 2. 14 + debian changes diff again; Outside of some autotools noise, the … This was caused due to an unlimited parsing depth when parsing json arrays and is now fixed by limiting the depth to 2048. For debian 7 wheezy, this problem has been fixed in version 2. 3. 1 … We seem to have multiple problems here: 1) software that is not shipped by debian and uses a statically linked or private copy of libssl crashes, because libmount1 pulls in libssl1. 1, transitively.

For debian 7 wheezy, this problem has been fixed in version 2. 3. 1 … We seem to have multiple problems here: 1) software that is not shipped by debian and uses a statically linked or private copy of libssl crashes, because libmount1 pulls in libssl1. 1, transitively.