[SECURITY] Fedora 13 Update: python-cjson-1.0.5-5.fc13

updates at fedoraproject.org updates at fedoraproject.org
Tue Jul 20 22:40:04 UTC 2010


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-10728
2010-07-06 16:21:27
--------------------------------------------------------------------------------

Name        : python-cjson
Product     : Fedora 13
Version     : 1.0.5
Release     : 5.fc13
URL         : http://pypi.python.org/pypi/python-cjson
Summary     : Fast JSON encoder/decoder for Python
Description :
JSON stands for JavaScript Object Notation and is a text based lightweight
data exchange format which is easy for humans to read/write and for machines
to parse/generate. JSON is completely language independent and has multiple
implementations in most of the programming languages, making it ideal for
data exchange and storage.

The module is written in C and it is up to 250 times faster when compared to
the other python JSON implementations which are written directly in python.
This speed gain varies with the complexity of the data and the operation and
is the the range of 10-200 times for encoding operations and in the range of
100-250 times for decoding operations.

--------------------------------------------------------------------------------
ChangeLog:

* Sat Jul  3 2010 Felix Schwarz <felix.schwarz at oss.schwarz.eu> - 1.0.5-5
- CVE-2010-1666 (fixed by including a patch from Ubuntu, see Launchpad 585274)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #610877 - CVE-2010-1666 python-cjson: Buffer overflow (crash) when encoding wide Unicode characters on UTF-32/UCS-4
        https://bugzilla.redhat.com/show_bug.cgi?id=610877
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update python-cjson' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list