-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 31 May 2020 15:42:31 +0200 Source: json-c Binary: libjson-c2 libjson-c-dev libjson-c2-dbg libjson-c-doc libjson0-dev libjson0 Architecture: source amd64 all Version: 0.11-4+deb8u1 Distribution: jessie-security Urgency: medium Maintainer: fabien boucher <fabien.dot.boucher@gmail.com> Changed-By: Mike Gabriel <sunweaver@debian.org> Description: libjson-c-dev - JSON manipulation library - development files libjson-c-doc - JSON manipulation library - documentation files libjson-c2 - JSON manipulation library - shared library libjson-c2-dbg - JSON manipulation library - debug symbols libjson0 - JSON manipulation library (transitional package) libjson0-dev - JSON manipulation library (transitional package) Closes: 960326 Changes: json-c (0.11-4+deb8u1) jessie-security; urgency=medium . * Non-maintainer upload by the LTS team. * CVE-2020-12762: Fix integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. (Closes: #960326). * debian/rules: + Ensure test wrapper scripts (test/*.tests) are executable. Checksums-Sha1: 6fc8aa3fdb25a0a2196536c067d1e50580c8616b 2243 json-c_0.11-4+deb8u1.dsc 5d0377d2cc4a1af324d5aeb5b63032d1d026aacd 557263 json-c_0.11.orig.tar.gz abcf26a734dc8d36c983de02bc1de5118339c110 275464 json-c_0.11-4+deb8u1.debian.tar.xz d322c9090ce9276f7ba78b0793934ef031d28289 25466 libjson-c2_0.11-4+deb8u1_amd64.deb b8c6ccd3b7db960b131d70a6852f4a1c97821a29 35848 libjson-c-dev_0.11-4+deb8u1_amd64.deb 464e3c244afbfde2fae272782b0eaa9753012274 43308 libjson-c2-dbg_0.11-4+deb8u1_amd64.deb 3304db7047cbe33a5d7c78cb0562af9ff3935d5b 18854 libjson-c-doc_0.11-4+deb8u1_all.deb a0cd5e9d28b9580f7abe7c5aa4bfde8f198467cc 1230 libjson0-dev_0.11-4+deb8u1_amd64.deb ceed67562b0b0bebe3c90636e99c6ae4e92e5780 1110 libjson0_0.11-4+deb8u1_amd64.deb Checksums-Sha256: b2557f426e0a863f427342bea2962d64f9be6f0fef07058e3b989c11590315f6 2243 json-c_0.11-4+deb8u1.dsc 28dfc65145dc0d4df1dfe7701ac173c4e5f9347176c8983edbfac9149494448c 557263 json-c_0.11.orig.tar.gz 08044ecd82cfbd8df853e57b7c1412a3a57371f532a976ea8d358f9c6342f40c 275464 json-c_0.11-4+deb8u1.debian.tar.xz d304fe5f5e02ebb79db5ef7564320f6502a64b3e9f8d74a672ca4e4e4961bc53 25466 libjson-c2_0.11-4+deb8u1_amd64.deb 24643037e63426c1aa48f13ee5516b4312cae452ee22725e5ba69c724c44792f 35848 libjson-c-dev_0.11-4+deb8u1_amd64.deb 0d2da4dfd9e07dd689f63a151d8e39408a5b009c7de1182afc98cd0f15e55fe8 43308 libjson-c2-dbg_0.11-4+deb8u1_amd64.deb 915a3fba4f8f41d4a575b93a22a17962ccfce0d16ca4d5edf1ce23d029da1db1 18854 libjson-c-doc_0.11-4+deb8u1_all.deb 0ff384fd315c9ceb9e4bd21b31d8200136a03af4d6959f21403acce81cd52987 1230 libjson0-dev_0.11-4+deb8u1_amd64.deb eabf2a144ce91023daee891a99f044abb36c1d36e25c7e97ba67980fc498208f 1110 libjson0_0.11-4+deb8u1_amd64.deb Files: fc239d51c45c9bc238e51105001dc427 2243 libs extra json-c_0.11-4+deb8u1.dsc aa02367d2f7a830bf1e3376f77881e98 557263 libs extra json-c_0.11.orig.tar.gz 139bf07ae371e3562268ea58d9aa18c9 275464 libs extra json-c_0.11-4+deb8u1.debian.tar.xz a7c230cdeb058f685f80bcc2aec84a54 25466 libs extra libjson-c2_0.11-4+deb8u1_amd64.deb 571497344594c0f8d1599af8fc69c2f7 35848 libdevel extra libjson-c-dev_0.11-4+deb8u1_amd64.deb e652714ad2eb5a5aa956aaa130712399 43308 debug extra libjson-c2-dbg_0.11-4+deb8u1_amd64.deb cb16779cdd7dc8219ed8d8e56618624c 18854 doc extra libjson-c-doc_0.11-4+deb8u1_all.deb 3d28fa624b7a0f059d85cdf5d6989c44 1230 oldlibs extra libjson0-dev_0.11-4+deb8u1_amd64.deb 68229124fda3487f3c37339ae19d6f47 1110 oldlibs extra libjson0_0.11-4+deb8u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQJJBAEBCAAzFiEEm/uu6GwKpf+/IgeCmvRrMCV3GzEFAl7TtOMVHHN1bndlYXZl ckBkZWJpYW4ub3JnAAoJEJr0azAldxsxLSoP/jQIoBAxgj1kfahQHPNXeHBMYewx Y998QsPj735AFgoetE1vUpIg1gtRp5PUIAr+La9G+JTP2fl4mwIbTNj7iHocQr4A CLQ4r7LpLmAQm4mi6tzrFWN88JtHwvBLBnDYtDwTrwKZNMy1LUWRsz4SIwMKJC6c MU7cabsV/YYhTRTYqxWKaSAPbqk9ydfzjAxyWei6Kj+1dxMaMQAB+9a001mNc11M seNuXP0MWINbIYiKrlNFDrbNi8GHqyasW/FYK1Zh2oytVawg1Kj0Cz5AIQ/Wt9R6 M1LsQYNfn3Fa3sN0VT+cpSdvv4++h/8hipfOUZPXKeCcDLDVOnY4oNwKO69FW/TJ GdL0MiAdq6rhtBs84pr+NGdh1yGUipbRZpRV1xo/zvEZhDJ/XLh5yEgfcssDLK1F 29qQw41SjApiuUMhvYl7Uokk7lTjztUVykPZXDa7zyM9w/PfkidQAYSiaSJxew3N 950RIuxNqb0AJI12Yg3jJSGkzIDWS9hMb+LwPouZF1l+NqI+XpPRAl94ardqFIiy g0x6C3yK+sn4fNq2Ra4YMJVr0g1i0MAMmjXM8bWooqsvj5Bsutt0Je1UYfDJtFH2 fPn1QOPFl+qfj/ODqb9gigE0hz7Ada4eVAllV1aNozp4gdbXRp6ZDWsx5Mypmcsq Y6RKWTcp3cewwtCk =c45z -----END PGP SIGNATURE-----