GNU bug report logs - #41525
CVE-2020-12762: json-c

Previous Next

Package: guix;

Reported by: Lars-Dominik Braun <lars <at> 6xq.net>

Date: Mon, 25 May 2020 12:08:02 UTC

Severity: normal

Tags: security

Done: Maxim Cournoyer <maxim.cournoyer <at> gmail.com>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: help-debbugs <at> gnu.org (GNU bug Tracking System)
To: Maxim Cournoyer <maxim.cournoyer <at> gmail.com>
Cc: tracker <at> debbugs.gnu.org
Subject: bug#41525: closed (CVE-2020-12762: json-c)
Date: Wed, 21 Oct 2020 04:28:02 +0000
[Message part 1 (text/plain, inline)]
Your message dated Wed, 21 Oct 2020 00:27:39 -0400
with message-id <875z74430k.fsf <at> gmail.com>
and subject line Re: bug#41525: CVE-2020-12762: json-c
has caused the debbugs.gnu.org bug report #41525,
regarding CVE-2020-12762: json-c
to be marked as done.

(If you believe you have received this mail in error, please contact
help-debbugs <at> gnu.org.)


-- 
41525: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=41525
GNU Bug Tracking System
Contact help-debbugs <at> gnu.org with problems
[Message part 2 (message/rfc822, inline)]
From: Lars-Dominik Braun <lars <at> 6xq.net>
To: bug-guix <at> gnu.org
Subject: CVE-2020-12762: json-c
Date: Mon, 25 May 2020 14:06:47 +0200
Hi,

our package json-c is vulnerable to CVE-2020-12762[1]. Be careful when
applying the “fix”, since it broke a lot of packages on Ubuntu and
Gentoo[2] in the past week.

Lars

[1] https://nvd.nist.gov/vuln/detail/CVE-2020-12762
[2] https://bugs.gentoo.org/722150



[Message part 3 (message/rfc822, inline)]
From: Maxim Cournoyer <maxim.cournoyer <at> gmail.com>
To: Lars-Dominik Braun <lars <at> 6xq.net>
Cc: 41525-done <at> debbugs.gnu.org
Subject: Re: bug#41525: CVE-2020-12762: json-c
Date: Wed, 21 Oct 2020 00:27:39 -0400
Hello,

Lars-Dominik Braun <lars <at> 6xq.net> writes:

> Hi,
>
> our package json-c is vulnerable to CVE-2020-12762[1]. Be careful when
> applying the “fix”, since it broke a lot of packages on Ubuntu and
> Gentoo[2] in the past week.
>
> Lars
>
> [1] https://nvd.nist.gov/vuln/detail/CVE-2020-12762
> [2] https://bugs.gentoo.org/722150

Thanks for the report!

This was fixed by Efraim on the 6th of August, with commit
10b40489742bdaa0d193c00dff1446b11c081f6a.

Closing,

Maxim


This bug report was last modified 4 years and 218 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.