[DSA 6000-1] libcpanel-json-xs-perl security update

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6000-1                   [email protected]
https://www.debian.org/security/                     Salvatore Bonaccorso
September 11, 2025                    https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : libcpanel-json-xs-perl
CVE ID         : CVE-2025-40929

Michael Hudak discovered a flaw in libcpanel-json-xs-perl, a module for
fast and correct serialising to JSON. An integer buffer overflow causing
a segfault when parsing specially crafted JSON, may allow an attacker to
mount a denial-of-service attack or cause other unspecified impact.

For the oldstable distribution (bookworm), this problem has been fixed
in version 4.35-1+deb12u1.

For the stable distribution (trixie), this problem has been fixed in
version 4.39-2~deb13u1.

We recommend that you upgrade your libcpanel-json-xs-perl packages.

For the detailed security status of libcpanel-json-xs-perl please refer
to its security tracker page at:
https://security-tracker.debian.org/tracker/libcpanel-json-xs-perl

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmjDJWZfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0QcGBAAhomvzAkpvE/ZVP/0sKTUzWTxCJlllzjtYE7H4yNw4pUwE8Dvyb/sAtt5
aUcqrobxUAvwzZZ31OYGCXeq5INuVlfzBUvoAnQDO370vdMaqqZKP0Vao42hurGb
tc9j+/+e02vn9EuGqjM+eGhhHdyZ4OFTBE7BuP1PniaTyFGTvnX/9nYBpVbmg7QT
BIzabjHMaal4LvUzzJbfqMZ0bMKJ4oEo3f/NRGJklwnx0FB7iDR/6Rul4kAKKCE+
jivrN+DW4Iz0bOAIsNSM+Rxhupd4gK/AOKN4ljH4J2Vr/BJRTgJG+yFfEzp+eKed
CE64gKmJTyuze3zTPxTEq3SjBpYES6cttmekN4hz0bZTfTVp+r5dUC0r8yuToEng
EZC1NxBPsd7XgvXZWLl6eodKoMY3igPzlPE6bJaK9O5AdfXi7aarKMMtsrw1NFUw
euK8WKEkY23+O3maYM7R4TeT3XYaSDlHzJbfhEFFr/vlP/GmI6jQK1oZQpDsEUue
0rb5WtvB8nptZgDc0SpJdkEacBrz6IDU3cZNfosNIRgrPnorkpAYHzoHjk4DWwtb
ZxLj8NvKxgp62pwkNf0hzCQOIFO4bnazSLC6EgBpKHfPBNU63ny9VTVOofn+orfx
l6X1JxrlO4DXxTAM3jvc/rPg1MzH5zkjc2lD94Ptsk6BnJhClPw=
=OXGz
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.