Summary: | <dev-java/json-smart-2.5.1: possible stack overflow | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Volkmar W. Pogatzki <gentoo> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | CONFIRMED --- | ||
Severity: | normal | CC: | java, proxy-maint, tharvik |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://research.jfrog.com/vulnerabilities/stack-exhaustion-in-json-smart-leads-to-denial-of-service-when-parsing-malformed-json-xray-427633/ | ||
Whiteboard: | B3 [stable?] | ||
Package list: | Runtime testing required: | --- |
Description
Volkmar W. Pogatzki
2024-12-30 08:08:10 UTC
As far as I can tell from the sparse information json-smart v1 does not look affected. Upstream fix commit: https://github.com/netplex/json-smart-v2/commit/5b3205d051952d3100aa0db1535f6ba6226bd87a |