Back to bug 2188542

Who When What Removed Added
Sandipan Roy 2023-04-21 05:36:18 UTC CC abenaiss, aileenc, anstephe, asoldano, ataylor, avibelli, bbaranow, bgeorges, bmaxwell, boliveir, brian.stansberry, cdewolf, chazlett, clement.escoffier, cmoulliard, dandread, darran.lofthouse, dkreling, dosoudil, drichtar, ellin, fjuma, fmongiar, gmalinko, gsmet, hamadhan, hbraun, ikanello, ivassile, iweiss, janstey, jcantril, jmartisk, jnethert, jpavlik, jpechane, jpoth, jross, jscholz, lgao, lthon, max.andersen, mokumar, mosmerov, msochure, msvehla, nboldt, nwallace, pdelbell, pdrozd, peholase, periklis, pgallagh, pmackay, probinso, pskopek, rkieley, rowaters, rruss, rstancel, rsvoboda, sbiarozk, scorneli, sdouglas, shbose, smaestri, sthorger, swoodman, tcunning, tom.jenkinson, yfang
Sandipan Roy 2023-04-21 05:37:52 UTC Blocks 2180850
Sandipan Roy 2023-04-21 05:53:43 UTC Doc Text A flaw was found in the json-smart package. This security flaw ouccers when reaching a ‘[‘ or ‘{‘ character in the JSON input, the code parses an array or an object respectively. It was discovered that the 3PP does not have any limit to the nesting of such arrays or objects. Since the parsing of nested arrays and objects is done recursively, nesting too many of them can cause stack exhaustion (stack overflow) and crash the software.
Sandipan Roy 2023-04-21 05:54:53 UTC Fixed In Version json-smart 2.4.9, json-smart 2.4.10
RaTasha Tillery-Smith 2023-04-21 13:39:09 UTC Doc Text A flaw was found in the json-smart package. This security flaw ouccers when reaching a ‘[‘ or ‘{‘ character in the JSON input, the code parses an array or an object respectively. It was discovered that the 3PP does not have any limit to the nesting of such arrays or objects. Since the parsing of nested arrays and objects is done recursively, nesting too many of them can cause stack exhaustion (stack overflow) and crash the software. A flaw was found in the json-smart package. This security flaw occurs when reaching a ‘[‘ or ‘{‘ character in the JSON input, and the code parses an array or an object, respectively. The 3PP does not have any limit to the nesting of such arrays or objects. Since nested arrays and objects are parsed recursively, nesting too many of them can cause stack exhaustion (stack overflow) and crash the software.
Avinash Hanwate 2023-04-24 04:32:39 UTC CC dfreiber, jburrell, rogbas, vkumar
errata-xmlrpc 2023-05-03 14:05:34 UTC Link ID Red Hat Product Errata RHSA-2023:2099
errata-xmlrpc 2023-05-03 14:07:24 UTC Link ID Red Hat Product Errata RHSA-2023:2100
Product Security DevOps Team 2023-05-03 20:36:42 UTC Resolution --- ERRATA
Status NEW CLOSED
Last Closed 2023-05-03 20:36:42 UTC
errata-xmlrpc 2023-05-17 12:29:45 UTC Link ID Red Hat Product Errata RHSA-2023:3179
errata-xmlrpc 2023-05-17 15:49:42 UTC Link ID Red Hat Product Errata RHSA-2023:3193
errata-xmlrpc 2023-05-18 09:54:45 UTC Link ID Red Hat Product Errata RHSA-2023:3223
errata-xmlrpc 2023-06-07 09:20:58 UTC Link ID Red Hat Product Errata RHSA-2023:3362
errata-xmlrpc 2023-06-15 00:15:11 UTC Link ID Red Hat Product Errata RHSA-2023:3610
errata-xmlrpc 2023-06-15 09:01:36 UTC Link ID Red Hat Product Errata RHSA-2023:3622
errata-xmlrpc 2023-06-15 15:24:23 UTC Link ID Red Hat Product Errata RHSA-2023:3641
errata-xmlrpc 2023-06-19 10:13:20 UTC Link ID Red Hat Product Errata RHSA-2023:3663
errata-xmlrpc 2023-06-28 15:59:24 UTC Link ID Red Hat Product Errata RHSA-2023:3906
errata-xmlrpc 2023-06-29 20:08:42 UTC Link ID Red Hat Product Errata RHSA-2023:3954

Back to bug 2188542