stable

python-ujson-5.4.0-1.fc36

FEDORA-2022-1b2b8d5177 created by music a year ago for Fedora 36

Security fix for CVE-2022-31116 and CVE-2022-31117.

5.4.0

Added

  • Add support for arbitrary size integers

Fixed

  • CVE-2022-31116: Replace wchar_t string decoding implementation with a uint32_t-based one; fix handling of surrogates on decoding
  • CVE-2022-31117: Potential double free of buffer during string decoding
  • Fix memory leak on encoding errors when the buffer was resized
  • Integer parsing: always detect overflows
  • Fix handling of surrogates on encoding

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2022-1b2b8d5177

This update has been submitted for testing by music.

a year ago

This update's test gating status has been changed to 'ignored'.

a year ago

music edited this update.

a year ago

This update has been pushed to testing.

a year ago

This update has been submitted for stable by bodhi.

a year ago

This update has been pushed to stable.

a year ago

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
a year ago
in testing
a year ago
in stable
a year ago
modified
a year ago
BZ#2103379 python-ujson-5.4.0 is available
0
0
BZ#2104739 CVE-2022-31117 python-ujson: Potential double free of buffer during string decoding
0
0
BZ#2104740 CVE-2022-31116 python-ujson: improper decoding of escaped surrogate characters may lead to string corruption, key confusion or value overwriting
0
0
BZ#2106986 CVE-2022-31117 python-ujson: Potential double free of buffer during string decoding [fedora-all]
0
0
BZ#2106990 CVE-2022-31116 python-ujson: improper decoding of escaped surrogate characters may lead to string corruption, key confusion or value overwriting [fedora-all]
0
0

Automated Test Results