Bugzilla – Bug 1206400
VUL-0: CVE-2022-45685: jettison: StackOverflow on malformed input
Last modified: 2024-05-03 09:30:20 UTC
CVE-2022-45685 A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data. Upstream commit: https://github.com/jettison-json/jettison/commit/19ae19ff57d00dbfa6f6c3af4fc4cb14fb5ca2df References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-45685 https://www.cve.org/CVERecord?id=CVE-2022-45685 https://github.com/jettison-json/jettison/issues/54
Affected: - SUSE:SLE-15-SP2:Update - openSUSE:Backports:SLE-15-SP3:Update - openSUSE:Factory
This one is fixed. Not sure why the bot did not mention Factory, but the packages in factory and sle15 are ~identical.
done, closing