Your message dated Thu, 28 Dec 2023 20:49:53 +0000
with message-id <[email protected]>
and subject line Bug#1059287: fixed in cjson 1.7.17-1
has caused the Debian Bug report #1059287,
regarding cjson: CVE-2023-50471 CVE-2023-50472
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1059287: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1059287
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: cjson
X-Debbugs-CC: [email protected]
Severity: normal
Tags: security

Hi,

The following vulnerabilities were published for cjson.

They appear to be rather bogus and not cross any security boundaries,
please doublecheck:

CVE-2023-50471[0]:
| cJSON v1.7.16 was discovered to contain a segmentation violation via
| the function cJSON_InsertItemInArray at cJSON.c.

https://github.com/DaveGamble/cJSON/issues/802
Fixed by: 
https://github.com/DaveGamble/cJSON/commit/60ff122ef5862d04b39b150541459e7f5e35add8

CVE-2023-50472[1]:
| cJSON v1.7.16 was discovered to contain a segmentation violation via
| the function cJSON_SetValuestring at cJSON.c.

https://github.com/DaveGamble/cJSON/issues/803
Fixed by: 
https://github.com/DaveGamble/cJSON/commit/60ff122ef5862d04b39b150541459e7f5e35add8

If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-50471
    https://www.cve.org/CVERecord?id=CVE-2023-50471
[1] https://security-tracker.debian.org/tracker/CVE-2023-50472
    https://www.cve.org/CVERecord?id=CVE-2023-50472

Please adjust the affected versions in the BTS as needed.

--- End Message ---
--- Begin Message ---
Source: cjson
Source-Version: 1.7.17-1
Done: Boyuan Yang <[email protected]>

We believe that the bug you reported is fixed in the latest version of
cjson, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Boyuan Yang <[email protected]> (supplier of updated cjson package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 28 Dec 2023 15:17:13 -0500
Source: cjson
Architecture: source
Version: 1.7.17-1
Distribution: unstable
Urgency: medium
Maintainer: Boyuan Yang <[email protected]>
Changed-By: Boyuan Yang <[email protected]>
Closes: 1059287
Changes:
 cjson (1.7.17-1) unstable; urgency=medium
 .
   * New upstream release.
     (Closes: #1059287) (CVE-2023-50471) (CVE-2023-50472)
Checksums-Sha1:
 bdc9b02410a7cd399ae4507965f4973a3461555a 1867 cjson_1.7.17-1.dsc
 486d8f7beedb238473a2e6940d53f9867e551fa4 353748 cjson_1.7.17.orig.tar.gz
 07638040b49e4243d7c484a6e38e13b7eb9cc4a2 3772 cjson_1.7.17-1.debian.tar.xz
 b6fbf29f423e5b8ffb01426fad136c80bdda5629 7242 cjson_1.7.17-1_amd64.buildinfo
Checksums-Sha256:
 6a943974726cc31b7c52c3c3974fd080a1a55981ac6502ec0edb3569174b85dc 1867 
cjson_1.7.17-1.dsc
 c91d1eeb7175c50d49f6ba2a25e69b46bd05cffb798382c19bfb202e467ec51c 353748 
cjson_1.7.17.orig.tar.gz
 20bca09f988b32142f5f6be00536c9df2c40839f2ccf6c4bc3cb229d74cdb169 3772 
cjson_1.7.17-1.debian.tar.xz
 362e5379c4c90936083db7ab18d6b87dd0603222c8c4e40515ae40c0d629a011 7242 
cjson_1.7.17-1_amd64.buildinfo
Files:
 c6906b126197c68e99d33bebfb25f994 1867 libs optional cjson_1.7.17-1.dsc
 344409fa865ca3440be94089d1cc37ac 353748 libs optional cjson_1.7.17.orig.tar.gz
 fb37cd68281aadaea2f82c0ca54d98f4 3772 libs optional 
cjson_1.7.17-1.debian.tar.xz
 6bd5e76f3b53aa903bab5678ac4453bc 7242 libs optional 
cjson_1.7.17-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEfncpR22H1vEdkazLwpPntGGCWs4FAmWN2HkACgkQwpPntGGC
Ws5h2Q/+Mix7GaQED2KOUEZANbIRBWwpmPw2yixuVbKik0fv2yBUKVnugQf6O//5
4U0i48Br8Qb2RpSiWoIQ4G67FfspXPhs/4GXxszQXUVjb7IbnLtX3truRcMQ2Soq
Kt0uR3/d8J8wgJCpftCQOlYbufVfkh3yzwmohzPRrBt77rMDpYBNJ4P3ThMEhCiU
Pnk3CSM86/Uq4K6BbSRub1bfe1POGCBJBhAmXmKbTwhJZlAkZZq61U/DWoGIsNnA
OZ2zBPuOj+weK26LMuO8gpvtJliY6zAbmUONpZiui3UB8bZ7MebKyWyZ8GG1r25n
bzLbw5Zg9ah94d/FKmP5ZPLsUEhLw9xQBvGxaYA1wG/UjFKaJPuZMFLv/rZFyK/K
fiAV+VCR5ND9KIc29WzUak8XO9K6kLae+WXOyNbNf41OodiOIsv3cfZ5ZBf1PvVw
kvzhCFzH8jok8xqrI/NIm8ssg/SxkII6gC8dD1IZ0E0aUNKZI/1OELD8RMgXDV3Y
seKffb/A3C9VEGANJUR+ieKd7Zi2Sk0gwEmW+sy6yzcJ52D4uj7ozZGQodek8bx6
wPnIQjCFqQ884UlQ/Uf6qjn0o8tXLHHNvYSKYhIVdOATj4LWuDBSm3C3iX+2ZgIP
bjYgcQ37crwixsH/9v5mUWvzABY8uk6kVqhnFnl+AUsTQEHHbf8=
=xdMp
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to