CVE-2022-48623

NameCVE-2022-48623
DescriptionThe Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libcpanel-json-xs-perl (PTS)bullseye4.25-1vulnerable
bookworm4.35-1fixed
sid, trixie4.38-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libcpanel-json-xs-perlsource(unstable)4.35-1

Notes

[bullseye] - libcpanel-json-xs-perl <no-dsa> (Minor issue)
[buster] - libcpanel-json-xs-perl <no-dsa> (Minor issue)
https://github.com/rurban/Cpanel-JSON-XS/issues/208
Fixed by: https://github.com/rurban/Cpanel-JSON-XS/commit/41f32396eee9395a40f9ed80145c37622560de9b (4.33)

Search for package or bug name: Reporting problems