Debian Security Advisory
DLA-471-1 jansson -- LTS security update
- Date Reported:
- 13 May 2016
- Affected Packages:
- jansson
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 823238.
In Mitre's CVE dictionary: CVE-2016-4425. - More information:
-
Applications that depend on Jansson, a C library for encoding, decoding and manipulating JSON data, could crash due to stack exhaustion while parsing a JSON file. This was caused due to an unlimited parsing depth when parsing JSON arrays and is now fixed by limiting the depth to 2048.
For Debian 7
Wheezy
, this problem has been fixed in version 2.3.1-2+deb7u1.We recommend that you upgrade your jansson packages.