Debian Package Tracker
Register | Log in
Subscribe

cjson

Choose email to subscribe with

general
  • source: cjson (main)
  • version: 1.7.18-3
  • maintainer: Maytham Alsudany (DMD)
  • arch: any
  • std-ver: 4.7.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.7.10-1.1+deb10u1
  • o-o-sec: 1.7.10-1.1+deb10u2
  • oldstable: 1.7.14-1+deb11u1
  • old-p-u: 1.7.14-1+deb11u1
  • stable: 1.7.15-1+deb12u2
  • testing: 1.7.18-3
  • unstable: 1.7.18-3
versioned links
  • 1.7.10-1.1+deb10u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.7.10-1.1+deb10u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.7.14-1+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.7.15-1+deb12u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.7.18-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libcjson-dev
  • libcjson1
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2023-26819: cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.
Created: 2025-04-20 Last update: 2025-05-24 04:31
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2023-26819: cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.
Created: 2025-04-20 Last update: 2025-05-24 04:31
2 security issues in bullseye high

There are 2 open security issues in bullseye.

1 important issue:
  • CVE-2023-53154: parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.
1 issue postponed or untriaged:
  • CVE-2023-26819: (postponed; to be fixed through a stable update) cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.
Created: 2025-05-23 Last update: 2025-05-24 04:31
2 security issues in bookworm high

There are 2 open security issues in bookworm.

1 important issue:
  • CVE-2023-53154: parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.
1 issue left for the package maintainer to handle:
  • CVE-2023-26819: (needs triaging) cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.

You can find information about how to handle this issue in the security team's documentation.

Created: 2025-04-20 Last update: 2025-05-24 04:31
Build log checks report 1 warning low
Build log checks report 1 warning
Created: 2018-08-13 Last update: 2018-08-13 20:07
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.7.0).
Created: 2025-02-21 Last update: 2025-02-27 13:25
news
[rss feed]
  • [2024-10-11] Accepted cjson 1.7.15-1+deb12u2 (source) into proposed-updates (Debian FTP Masters) (signed by: Boyuan Yang)
  • [2024-07-01] Accepted cjson 1.7.14-1+deb11u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Maytham Alsudany)
  • [2024-06-25] cjson 1.7.18-3 MIGRATED to testing (Debian testing watch)
  • [2024-06-23] Accepted cjson 1.7.18-3 (source) into unstable (Maytham Alsudany)
  • [2024-06-23] Accepted cjson 1.7.18-2 (source) into unstable (Maytham Alsudany)
  • [2024-06-22] Accepted cjson 1.7.18-1 (source) into unstable (Maytham Alsudany) (signed by: bage@debian.org)
  • [2024-06-19] Accepted cjson 1.7.15-1+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: bage@debian.org)
  • [2024-03-28] cjson 1.7.17-2 MIGRATED to testing (Debian testing watch)
  • [2024-03-22] Accepted cjson 1.7.17-2 (source) into unstable (Boyuan Yang)
  • [2024-01-04] cjson 1.7.17-1 MIGRATED to testing (Debian testing watch)
  • [2023-12-30] Accepted cjson 1.7.10-1.1+deb10u2 (source) into oldoldstable (Thorsten Alteholz)
  • [2023-12-28] Accepted cjson 1.7.17-1 (source) into unstable (Boyuan Yang)
  • [2023-11-07] cjson 1.7.16-2 MIGRATED to testing (Debian testing watch)
  • [2023-11-01] Accepted cjson 1.7.16-2 (source) into unstable (Boyuan Yang)
  • [2023-07-17] cjson 1.7.16-1 MIGRATED to testing (Debian testing watch)
  • [2023-07-11] Accepted cjson 1.7.16-1 (source) into unstable (Boyuan Yang)
  • [2021-09-04] cjson 1.7.15-1 MIGRATED to testing (Debian testing watch)
  • [2021-08-29] Accepted cjson 1.7.15-1 (source) into unstable (Boyuan Yang)
  • [2021-01-30] Accepted cjson 1.7.10-1.1+deb10u1 (source) into proposed-updates->stable-new, proposed-updates (Debian FTP Masters) (signed by: Boyuan Yang)
  • [2020-09-12] cjson 1.7.14-1 MIGRATED to testing (Debian testing watch)
  • [2020-09-06] Accepted cjson 1.7.14-1 (source) into unstable (Boyuan Yang)
  • [2020-05-29] cjson 1.7.13-1 MIGRATED to testing (Debian testing watch)
  • [2020-05-23] Accepted cjson 1.7.13-1 (source) into unstable (Boyuan Yang)
  • [2020-05-22] Accepted cjson 1.7.10-2 (source) into unstable (Boyuan Yang)
  • [2019-05-21] cjson 1.7.10-1.1 MIGRATED to testing (Debian testing watch)
  • [2019-05-16] Accepted cjson 1.7.10-1.1 (source amd64) into unstable (Gordon Ball) (signed by: Yanhao Mo)
  • [2019-01-12] cjson 1.7.10-1 MIGRATED to testing (Debian testing watch)
  • [2019-01-07] Accepted cjson 1.7.10-1 (source amd64) into unstable (Yanhao Mo)
  • [2018-10-19] cjson 1.7.8-1 MIGRATED to testing (Debian testing watch)
  • [2018-10-14] Accepted cjson 1.7.8-1 (source amd64) into unstable (Yanhao Mo)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, checks, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.7.18-3
  • 1 bug

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing