Your message dated Sun, 06 Jul 2025 17:47:55 +0000
with message-id <[email protected]>
and subject line unblock cjson
has caused the Debian Bug report #1108861,
regarding unblock: cjson/1.7.18-3.1
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1108861: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1108861
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: release.debian.org
Severity: normal
X-Debbugs-Cc: [email protected], Adrian Bunk <[email protected]>,
[email protected], Maytham Alsudany <[email protected]>,
[email protected]
Control: affects -1 + src:cjson
User: [email protected]
Usertags: unblock
Hi,
Please unblock package cjson
[ Reason ]
cjson 1.7.18-3 was prone to CVE-2023-26819, fixed by Adrian in the
1.7.18-3.1 NMU, cf. #1103687.
[ Impact ]
cjson in trixie remains vulnerable so far to CVE-2023-26819. There is
as well a pending cjson bookworm-pu update covering as well this CVE.
[ Tests ]
I have done none. There is a test covering the change.
[ Risks ]
Probably low, upstream change applied.
[ Checklist ]
[x] all changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in testing
unblock cjson/1.7.18-3.1
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Unblocked cjson.
--- End Message ---