openSUSE-SU-2024:0139-1

    Dashboard / Vulnerabilities / openSUSE-SU-2024:0139-1

    openSUSE-SU-2024:0139-1

    Published: 25 May 2024Last Modified: 4 Feb 2026

    Summary: Security update for cJSON

    Details: This update for cJSON fixes the following issues: - Update to 1.7.18: * CVE-2024-31755: NULL pointer dereference via cJSON_SetValuestring() (boo#1223420) * Remove non-functional list handling of compiler flags * Fix heap buffer overflow * remove misused optimization flag -01 * Set free'd pointers to NULL whenever they are not reassigned immediately after - Update to version 1.7.17 (boo#1218098, CVE-2023-50472, boo#1218099, CVE-2023-50471): * Fix null reference in cJSON_SetValuestring (CVE-2023-50472). * Fix null reference in cJSON_InsertItemInArray (CVE-2023-50471). - Update to 1.7.16: * Add an option for ENABLE_CJSON_VERSION_SO in CMakeLists.txt * Add cmake_policy to CMakeLists.txt * Add cJSON_SetBoolValue * Add meson documentation * Fix memory leak in merge_patch * Fix conflicting target names 'uninstall' * Bump cmake version to 3.0 and use new version syntax * Print int without decimal places * Fix 'cjson_utils-static' target not exist * Add allocate check for replace_item_in_object * Fix a null pointer crash in cJSON_ReplaceItemViaPointer

    Affected packages

    Package

    Name: cJSON

    Purl: pkg:rpm/suse/cJSON&distro=SUSE%20Package%20Hub%2015%20SP5

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.7.18-bp155.3.3.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    openSUSE-SU-2024:0139-1 | CVE-DB