Bug 22271 - json-c possible security issue with invalid free
Summary: json-c possible security issue with invalid free
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Nicolas Lécureuil
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-12-26 21:39 CET by David Walser
Modified: 2019-11-06 13:18 CET (History)
6 users (show)

See Also:
Source RPM: json-c-0.12.1-1.mga6.src.rpm
CVE:
Status comment: The validity of this issue is debatable


Attachments

Description David Walser 2017-12-26 21:39:21 CET
Fedora has issued an advisory on December 24:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/FYQLNAB3ZRR7U66VC3ANQHVU3MO5E3QD/

Corresponding upstream commit and pull request:
https://github.com/json-c/json-c/commit/5ea6a05bfa43c9ba438fbc0eaea600edd6d72b88
https://github.com/json-c/json-c/pull/389

Frankly I disagree with the patch and the reasoning.  It violates the "don't leave assertions turned on in production code" mantra, which in general can cause DoS issues, but in this case if the issue can be triggered, you already have that problem.  It sounds to me like "libu2f-server and sway" (whatever they are) are buggy and doing something wrong and this patch is pointless.
Comment 1 Marja Van Waes 2017-12-27 08:56:47 CET
Assigning to the registered maintainer.

CC'ing all packagers collectively and some committers, because the cauldron changelog of this package doesn't mention the maintainer.

CC: (none) => cjw, marja11, oe, olav, pkg-bugs
Assignee: bugsquad => mageia

David Walser 2018-02-02 18:26:48 CET

Status comment: (none) => The validity of this issue is debatable

Comment 2 Mike Rambo 2019-11-06 13:18:43 CET
Mageia 6 is EOL.

CC: (none) => mrambo
Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.