Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:1775-1

Опубликовано: 24 мая 2024
Источник: suse-cvrf

Описание

Security update for libfastjson

This update for libfastjson fixes the following issues:

  • CVE-2020-12762: Fixed integer overflow and out-of-bounds write via a large JSON file (bsc#1171479).

Список пакетов

Image SLES15-SP2-SAP-Azure-LI-BYOS-Production
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-BYOS-Azure
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-BYOS-EC2-HVM
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-BYOS-GCE
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-CHOST-BYOS-Aliyun
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-CHOST-BYOS-Azure
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-CHOST-BYOS-EC2
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-CHOST-BYOS-GCE
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-CHOST-BYOS-SAP-CCloud
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-HPC-BYOS-Azure
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-HPC-BYOS-EC2-HVM
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-HPC-BYOS-GCE
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-Micro-5-1-BYOS-Azure
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-Micro-5-1-BYOS-EC2-HVM
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-Micro-5-1-BYOS-GCE
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-Micro-5-2-BYOS-Azure
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-Micro-5-2-BYOS-EC2-HVM
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-Micro-5-2-BYOS-GCE
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-SAP-Azure-LI-BYOS-Production
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-SAP-BYOS-Azure
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-SAP-BYOS-EC2-HVM
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-SAP-BYOS-GCE
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-SAPCAL-Azure
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-SAPCAL-EC2-HVM
libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-SAPCAL-GCE
libfastjson4-0.99.8-150000.3.3.1
SUSE Enterprise Storage 7.1
libfastjson-devel-0.99.8-150000.3.3.1
libfastjson4-0.99.8-150000.3.3.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
libfastjson-devel-0.99.8-150000.3.3.1
libfastjson4-0.99.8-150000.3.3.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
libfastjson-devel-0.99.8-150000.3.3.1
libfastjson4-0.99.8-150000.3.3.1
SUSE Linux Enterprise Server 15 SP2-LTSS
libfastjson-devel-0.99.8-150000.3.3.1
libfastjson4-0.99.8-150000.3.3.1
SUSE Linux Enterprise Server 15 SP3-LTSS
libfastjson-devel-0.99.8-150000.3.3.1
libfastjson4-0.99.8-150000.3.3.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
libfastjson-devel-0.99.8-150000.3.3.1
libfastjson4-0.99.8-150000.3.3.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
libfastjson-devel-0.99.8-150000.3.3.1
libfastjson4-0.99.8-150000.3.3.1

Описание

json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.


Затронутые продукты
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production:libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production:libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-BYOS-Azure:libfastjson4-0.99.8-150000.3.3.1
Image SLES15-SP3-BYOS-EC2-HVM:libfastjson4-0.99.8-150000.3.3.1

Ссылки
Уязвимость SUSE-SU-2024:1775-1