|
|
Subscribe / Log in / New account

Debian alert DLA-4318-1 (libcpanel-json-xs-perl)

From:  Paride Legovini <paride@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4318-1] libcpanel-json-xs-perl security update
Date:  Tue, 30 Sep 2025 23:31:22 +0200
Message-ID:  <4f578e3f4f668ddb3460bf0caaa9cfa2@debian.org>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4318-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Paride Legovini September 30, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libcpanel-json-xs-perl Version : 4.25-1+deb11u1 CVE ID : CVE-2025-40929 A vulnerability has been fixed in libcpanel-json-xs-perl, a Perl module for serialising to JSON. CVE-2025-40929 Integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact For Debian 11 bullseye, this problem has been fixed in version 4.25-1+deb11u1. We recommend that you upgrade your libcpanel-json-xs-perl packages. For the detailed security status of libcpanel-json-xs-perl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libcpanel-jso... Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- wsC7BAEBCgBvBYJo3EwmCRDWWGGIPgFNuUcUAAAAAAAeACBzYWx0QG5vdGF0aW9u cy5zZXF1b2lhLXBncC5vcmdxXg19Qk0EfwfgMVpYfo23VrGainvUWHTQbAr7FoJG TRYhBFYa1YXu12aSG6jdltZYYYg+AU25AAD00ggAgbww2xuYETlZFHBMbgl5eqhC hUOToxnIpELVUDlEagn9ozFyK7wlWoCGEEyFHuXpgo8iep9tKLzPdOu2G3/i2sR0 KX03rvp4AgAKnc/eXu8EiUIYZENJK9/1lazsqzeKqr5/u1sTpDjd6WXRkc5GZ8tk bbe2EGozb6G/a50vZX+VRCXJ+uu+JFGZdkDPWWIdAVt/tOkUA52miYTI/DqFSPwo Pm6LrWrN2FXKuuab0VMBvvuHKIHUsJoXE51qjtTTbe/ThCtJHgd7KymDz0ZHZmVC SMGlox8PPjKGKgUF41f41gdQu0TG512qg0tx3twnKrTohaqQzsTe/ChpFX9S1A== =cp29 -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds