Vulnerability Bulletins

DSA-3577 jansson - security update

   
Affected software Debian
 
Gustavo Grieco discovered that jansson, a C library for encoding,decoding and manipulating JSON data, did not limit the recursion depthwhen parsing JSON arrays and objects. This could allow remote attackersto cause a denial of service (crash) via stack exhaustion, using craftedJSON data.

More info:

https://www.debian.org/security/2016/dsa-3577