Oval Definition:oval:org.mitre.oval:def:12644
Revision Date:2014-07-21Version:5
Title:DSA-1775-1 php-json-ext -- denial of service
Description:It was discovered that php-json-ext, a JSON serialiser for PHP, is prone to a denial of service attack, when receiving a malformed string via the json_decode function. For the oldstable distribution, this problem has been fixed in version 1.2.1-3.2+etch1. The stable distribution does not contain a separate php-json-ext package, but includes it in the php5 packages, which will be fixed soon. The testing distribution and the unstable distribution do not contain a separate php-json-ext package, but include it in the php5 packages. We recommend that you upgrade your php-json-ext packages.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-1271
DSA-1775-1
Platform(s):Debian GNU/Linux 4.0
Product(s):php-json-ext
Definition Synopsis
  • Debian GNU/Linux 4.0 is installed.
  • AND Packages section
  • php5-json DPKG is earlier than 1.2.1-3.2+etch1
  • OR php4-json DPKG is earlier than 1.2.1-3.2+etch1
  • BACK