{"id":"openSUSE-SU-2024:0139-1","summary":"Security update for cJSON","details":"This update for cJSON fixes the following issues:\n\n- Update to 1.7.18:\n  * CVE-2024-31755: NULL pointer dereference via cJSON_SetValuestring() (boo#1223420)\n  * Remove non-functional list handling of compiler flags\n  * Fix heap buffer overflow\n  * remove misused optimization flag -01\n  * Set free'd pointers to NULL whenever they are not reassigned\n    immediately after\n\n- Update to version 1.7.17 (boo#1218098, CVE-2023-50472,\n    boo#1218099, CVE-2023-50471):\n  * Fix null reference in cJSON_SetValuestring (CVE-2023-50472).\n  * Fix null reference in cJSON_InsertItemInArray (CVE-2023-50471).\n\n- Update to 1.7.16:\n  * Add an option for ENABLE_CJSON_VERSION_SO in CMakeLists.txt\n  * Add cmake_policy to CMakeLists.txt\n  * Add cJSON_SetBoolValue\n  * Add meson documentation\n  * Fix memory leak in merge_patch\n  * Fix conflicting target names 'uninstall'\n  * Bump cmake version to 3.0 and use new version syntax\n  * Print int without decimal places\n  * Fix 'cjson_utils-static' target not exist\n  * Add allocate check for replace_item_in_object\n  * Fix a null pointer crash in cJSON_ReplaceItemViaPointer\n","modified":"2026-02-04T03:51:15.787085Z","published":"2024-05-25T08:47:48Z","related":["CVE-2023-50471","CVE-2023-50472","CVE-2024-31755"],"upstream":["CVE-2023-50471","CVE-2023-50472","CVE-2024-31755"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/36QNMKFWNRJX3XHLNGZ3DNLMLIHSRF4U/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218098"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218099"},{"type":"REPORT","url":"https://bugzilla.suse.com/1223420"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-50471"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-50472"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-31755"}],"affected":[{"package":{"name":"cJSON","ecosystem":"SUSE:Package Hub 15 SP5","purl":"pkg:rpm/suse/cJSON&distro=SUSE%20Package%20Hub%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.18-bp155.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"cJSON-devel":"1.7.18-bp155.3.3.1","libcjson1":"1.7.18-bp155.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2024:0139-1.json"}},{"package":{"name":"cJSON","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/cJSON&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.18-bp155.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"libcjson1":"1.7.18-bp155.3.3.1","cJSON-devel":"1.7.18-bp155.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2024:0139-1.json"}}],"schema_version":"1.7.3"}