OESA-2025-2377
Dashboard / Vulnerabilities / OESA-2025-2377
Summary: cjson security update
Details: cJSON aims to be the dumbest possible parser that you can get your job done with. It's a single file of C, and a single header file. %package devel Summary: Development files for cJSON Requires: = - %description devel The cjson-devel package contains libraries and header files for developing applications that use cJSON. %prep %autosetup -n cJSON- -p1 Security Fix(es): cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.(CVE-2025-57052)
References: https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-2377, https://nvd.nist.gov/vuln/detail/CVE-2025-57052
Affected packages
Package
Name: cjson
Purl: pkg:rpm/openEuler/cjson&distro=openEuler-24.03-LTS-SP2
Affected ranges
Type: ECOSYSTEM
Events:
