ELA-762-1 libjettison-java security update

denial of service

2022-12-31
Packagelibjettison-java
Version1.5.3-1~deb9u1 (stretch)
Related CVEs CVE-2022-40150 CVE-2022-45685 CVE-2022-45693


Several flaws have been discovered in libjettison-java, a collection of StAX parsers and writers for JSON. Specially crafted user input may cause a denial of service via out-of-memory or stack overflow errors.

In addition a build failure related to the update was fixed in jersey1.



For Debian 9 stretch, these problems have been fixed in version 1.5.3-1~deb9u1.

We recommend that you upgrade your libjettison-java packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.