UbuntuUpdates.org

Package "python3-ujson"

Name: python3-ujson

Description:

ultra fast JSON encoder and decoder for Python 3

Latest version: 1.35-4ubuntu0.1
Release: focal (20.04)
Level: security
Repository: universe
Head package: ujson
Homepage: https://github.com/esnme/ultrajson

Links


Download "python3-ujson"


Other versions of "python3-ujson" in Focal

Repository Area Version
base universe 1.35-4build1
updates universe 1.35-4ubuntu0.1

Changelog

Version: 1.35-4ubuntu0.1 2024-02-14 04:06:54 UTC

  ujson (1.35-4ubuntu0.1) focal-security; urgency=medium

  * SECURITY UPDATE: buffer overflow
    - debian/patches/CVE-2021-45958.patch: a rewrite of the buffer
      reservation calls from scratch and fixes a bug in the debug
      buffer check.
    - CVE-2021-45958
  * debian/patches/CVE-2021-45958-tests-backport.patch: backport of
    tests from the patches to unittest.

 -- Allen Huang <email address hidden> Tue, 16 Jan 2024 11:22:01 +0000

CVE-2021-45958 UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for exa



About   -   Send Feedback to @ubuntu_updates