GNU bug report logs

#41525 CVE-2020-12762: json-c

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Reply or subscribe to this bug. View this bug as an mbox, status mbox, or maintainer mbox

Report forwarded to bug-guix@gnu.org:
bug#41525; Package guix. (Mon, 25 May 2020 12:08:02 GMT) (full text, mbox, link).


Acknowledgement sent to Lars-Dominik Braun <lars@6xq.net>:
New bug report received and forwarded. Copy sent to bug-guix@gnu.org. (Mon, 25 May 2020 12:08:02 GMT) (full text, mbox, link).


Message #5 received at submit@debbugs.gnu.org (full text, mbox, reply):

From: Lars-Dominik Braun <lars@6xq.net>
To: bug-guix@gnu.org
Subject: CVE-2020-12762: json-c
Date: Mon, 25 May 2020 14:06:47 +0200
Hi,

our package json-c is vulnerable to CVE-2020-12762[1]. Be careful when
applying the “fix”, since it broke a lot of packages on Ubuntu and
Gentoo[2] in the past week.

Lars

[1] https://nvd.nist.gov/vuln/detail/CVE-2020-12762
[2] https://bugs.gentoo.org/722150





Added tag(s) security. Request was from Ludovic Courtès <ludo@gnu.org> to control@debbugs.gnu.org. (Fri, 29 May 2020 14:38:02 GMT) (full text, mbox, link).


Reply sent to Maxim Cournoyer <maxim.cournoyer@gmail.com>:
You have taken responsibility. (Wed, 21 Oct 2020 04:28:02 GMT) (full text, mbox, link).


Notification sent to Lars-Dominik Braun <lars@6xq.net>:
bug acknowledged by developer. (Wed, 21 Oct 2020 04:28:02 GMT) (full text, mbox, link).


Message #12 received at 41525-done@debbugs.gnu.org (full text, mbox, reply):

From: Maxim Cournoyer <maxim.cournoyer@gmail.com>
To: Lars-Dominik Braun <lars@6xq.net>
Cc: 41525-done@debbugs.gnu.org
Subject: Re: bug#41525: CVE-2020-12762: json-c
Date: Wed, 21 Oct 2020 00:27:39 -0400
Hello,

Lars-Dominik Braun <lars@6xq.net> writes:

> Hi,
>
> our package json-c is vulnerable to CVE-2020-12762[1]. Be careful when
> applying the “fix”, since it broke a lot of packages on Ubuntu and
> Gentoo[2] in the past week.
>
> Lars
>
> [1] https://nvd.nist.gov/vuln/detail/CVE-2020-12762
> [2] https://bugs.gentoo.org/722150

Thanks for the report!

This was fixed by Efraim on the 6th of August, with commit
10b40489742bdaa0d193c00dff1446b11c081f6a.

Closing,

Maxim




bug archived. Request was from Debbugs Internal Request <help-debbugs@gnu.org> to internal_control@debbugs.gnu.org. (Wed, 18 Nov 2020 12:24:05 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sun Dec 22 05:59:38 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.