Описание
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libjson-java | fixed | 3.1.0+dfsg-1 | package | |
| libjson-java | no-dsa | bookworm | package | |
| libjson-java | no-dsa | bullseye | package | |
| libjson-java | no-dsa | buster | package | |
| jenkins-json | unfixed | package | ||
| jenkins-json | postponed | trixie | package | |
| jenkins-json | postponed | bookworm | package | |
| jenkins-json | no-dsa | bullseye | package | |
| jenkins-json | no-dsa | buster | package | |
| libjettison-java | unfixed | package | ||
| libjettison-java | postponed | trixie | package | |
| libjettison-java | postponed | bookworm | package | |
| libjettison-java | no-dsa | bullseye | package | |
| libjettison-java | no-dsa | buster | package |
Примечания
https://github.com/stleary/JSON-java/issues/758
https://github.com/stleary/JSON-java/issues/771
https://github.com/stleary/JSON-java/pull/772/
https://github.com/stleary/JSON-java/commit/dbb113176b143b519ad0a50b033a9997cc2248fe (20231013)
https://github.com/stleary/JSON-java/commit/16967f322ee65c301b48fa79bb681e38896fd212 (20231013)
https://github.com/stleary/JSON-java/commit/661114c50dcfd53bb041aab66f14bb91e0a87c8a (20231013)
https://github.com/kordamp/json-lib/issues/58
https://github.com/jettison-json/jettison/issues/86
EPSS
Связанные уязвимости
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
EPSS