First published: Thu May 28 2020(Updated: )
USN-4360-1 fixed a vulnerability in json-c. The security fix introduced a memory leak that was reverted in USN-4360-2 and USN-4360-3. This update provides the correct fix update for CVE-2020-12762. Original advisory details: It was discovered that json-c incorrectly handled certain JSON files. An attacker could possibly use this issue to execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libjson-c4 | <0.13.1+dfsg-7ubuntu0.3 | 0.13.1+dfsg-7ubuntu0.3 |
Ubuntu Linux | =20.04 | |
All of | ||
ubuntu/libjson-c4 | <0.13.1+dfsg-4ubuntu0.3 | 0.13.1+dfsg-4ubuntu0.3 |
Ubuntu Linux | =19.10 | |
All of | ||
ubuntu/libjson-c3 | <0.12.1-1.3ubuntu0.3 | 0.12.1-1.3ubuntu0.3 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/libjson-c2 | <0.11-4ubuntu2.6 | 0.11-4ubuntu2.6 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/libjson0 | <0.11-4ubuntu2.6 | 0.11-4ubuntu2.6 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/libjson-c2 | <0.11-3ubuntu1.2+esm3 | 0.11-3ubuntu1.2+esm3 |
Ubuntu Linux | =14.04 | |
All of | ||
ubuntu/libjson0 | <0.11-3ubuntu1.2+esm3 | 0.11-3ubuntu1.2+esm3 |
Ubuntu Linux | =14.04 | |
All of | ||
ubuntu/libjson0 | <0.9-1ubuntu1.4 | 0.9-1ubuntu1.4 |
Ubuntu Linux | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security advisory is USN-4360-4.
The title of this security advisory is USN-4360-4: json-c vulnerability.
The vulnerability that was fixed is CVE-2020-12762.
The software versions affected by this vulnerability are libjson-c4 version 0.13.1+dfsg-7ubuntu0.3, libjson-c4 version 0.13.1+dfsg-4ubuntu0.3, libjson-c3 version 0.12.1-1.3ubuntu0.3, libjson-c2 version 0.11-4ubuntu2.6, libjson0 version 0.11-4ubuntu2.6, libjson-c2 version 0.11-3ubuntu1.2+esm3, libjson0 version 0.11-3ubuntu1.2+esm3, and libjson0 version 0.9-1ubuntu1.4.
To fix this vulnerability, update libjson-c4 to version 0.13.1+dfsg-7ubuntu0.3 or later, libjson-c4 to version 0.13.1+dfsg-4ubuntu0.3 or later, libjson-c3 to version 0.12.1-1.3ubuntu0.3 or later, libjson-c2 to version 0.11-4ubuntu2.6 or later, libjson0 to version 0.11-4ubuntu2.6 or later, libjson-c2 to version 0.11-3ubuntu1.2+esm3 or later, libjson0 to version 0.11-3ubuntu1.2+esm3 or later, or libjson0 to version 0.9-1ubuntu1.4 or later.