{"id":"MGASA-2016-0198","summary":"Updated jansson packages fix CVE-2016-4425","details":"Updated jansson packages fix security vulnerability:\n\nGustavo Grieco discovered that jansson did not limit the recursion depth when\nparsing JSON arrays and objects. This could allow remote attackers to cause a\ndenial of service (crash) via stack exhaustion, using crafted JSON data\n(CVE-2016-4425).\n","modified":"2026-04-16T06:24:58.593381708Z","published":"2016-05-21T22:11:24Z","upstream":["CVE-2016-4425"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0198.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=18326"},{"type":"WEB","url":"https://www.debian.org/security/2016/dsa-3577"}],"affected":[{"package":{"name":"jansson","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/jansson?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4-4.1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0198.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}