Update Info

openSUSE-2024-139


Security update for cJSON


Type: security
Severity: important
Issued: 2024-05-25
Description:
This update for cJSON fixes the following issues:

- Update to 1.7.18:
  * CVE-2024-31755: NULL pointer dereference via cJSON_SetValuestring() (boo#1223420)
  * Remove non-functional list handling of compiler flags
  * Fix heap buffer overflow
  * remove misused optimization flag -01
  * Set free'd pointers to NULL whenever they are not reassigned
    immediately after

- Update to version 1.7.17 (boo#1218098, CVE-2023-50472,
    boo#1218099, CVE-2023-50471):
  * Fix null reference in cJSON_SetValuestring (CVE-2023-50472).
  * Fix null reference in cJSON_InsertItemInArray (CVE-2023-50471).

- Update to 1.7.16:
  * Add an option for ENABLE_CJSON_VERSION_SO in CMakeLists.txt
  * Add cmake_policy to CMakeLists.txt
  * Add cJSON_SetBoolValue
  * Add meson documentation
  * Fix memory leak in merge_patch
  * Fix conflicting target names 'uninstall'
  * Bump cmake version to 3.0 and use new version syntax
  * Print int without decimal places
  * Fix 'cjson_utils-static' target not exist
  * Add allocate check for replace_item_in_object
  * Fix a null pointer crash in cJSON_ReplaceItemViaPointer


              

Packages


  • cJSON-1.7.18-bp155.3.3.1