Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

openSUSE: 2024:0139-1 Important: cJSON Heap Overflow and Leak

opensuse
Calendar Grey May 25, 2024
Dist Opensuse Esm H88
Important Security Patch for cJSON in openSUSE addresses several vulnerabilities, significantly safeguarding system stability.
An update that fixes three vulnerabilities is now available

Description

This update for cJSON fixes the following issues:

- Update to 1.7.18:

* CVE-2024-31755: NULL pointer dereference via cJSON_SetValuestring()

(boo#1223420)

* Remove non-functional list handling of compiler flags

* Fix heap buffer overflow

* remove misused optimization flag -01

* Set free'd pointers to NULL whenever they are not reassigned

immediately after

- Update to version 1.7.17 (boo#1218098, CVE-2023-50472, boo#1218099,

CVE-2023-50471):

* Fix null reference in cJSON_SetValuestring (CVE-2023-50472).

* Fix null reference in cJSON_InsertItemInArray (CVE-2023-50471).

- Update to 1.7.16:

* Add an option for ENABLE_CJSON_VERSION_SO in CMakeLists.txt

* Add cmake_policy to CMakeLists.txt

* Add cJSON_SetBoolValue

* Add meson documentation

* Fix memory leak in merge_patch

* Fix conflicting target names 'uninstall'

* Bump cmake version to 3.0 and use new version syntax

* Print int...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP5:

zypper in -t patch openSUSE-2024-139=1

Package List

- openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64):

cJSON-devel-1.7.18-bp155.3.3.1

libcjson1-1.7.18-bp155.3.3.1

References

https://www.suse.com/security/cve/CVE-2023-50471.html

https://www.suse.com/security/cve/CVE-2023-50472.html

https://www.suse.com/security/cve/CVE-2024-31755.html

https://bugzilla.suse.com/1218098

https://bugzilla.suse.com/1218099

https://bugzilla.suse.com/1223420

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2024:0139-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP5 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here