Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 03 May 2016 00:22:48 +0000
From:      bugzilla-noreply@freebsd.org
To:        freebsd-ports-bugs@FreeBSD.org
Subject:   [Bug 209219] devel/jansson: denial of service vulnerability (CVE-2016-4425)
Message-ID:  <bug-209219-13@https.bugs.freebsd.org/bugzilla/>

next in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D209219

            Bug ID: 209219
           Summary: devel/jansson: denial of service vulnerability
                    (CVE-2016-4425)
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
               URL: http://www.openwall.com/lists/oss-security/2016/05/02/
                    1
                OS: Any
            Status: New
          Keywords: needs-patch, needs-qa, security
          Severity: Affects Some People
          Priority: ---
         Component: Individual Port(s)
          Assignee: vanilla@FreeBSD.org
          Reporter: junovitch@freebsd.org
                CC: ports-secteam@FreeBSD.org
             Flags: maintainer-feedback?(vanilla@FreeBSD.org),
                    merge-quarterly?
          Assignee: vanilla@FreeBSD.org

Maintainer of devel/jansson,
There is a report of an denial of service issue (CVE-2016-4425) in the libr=
ary
reported on oss-security
(http://www.openwall.com/lists/oss-security/2016/05/02/1).  The report
indicates this impacts jansson < 2.5 and the fix is still pending at
https://github.com/akheron/jansson/issues/282.  When there is a resolution,
this will need to filter down into the port and get a VuXML entry.

--=20
You are receiving this mail because:
You are the assignee for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-209219-13>