Bugzilla – Bug 1218098
VUL-0: CVE-2023-50472: cjson: segmentation violation in function cJSON_SetValuestring
Last modified: 2024-07-02 13:59:43 UTC
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-50472 https://github.com/DaveGamble/cJSON/issues/803
Tracking as affected: -openSUSE:Backports:SLE-15-SP4/cJSON -openSUSE:Backports:SLE-15-SP5/cJSON -openSUSE:Factory/cJSON
This is an autogenerated message for OBS integration: This bug (1218098) was mentioned in https://build.opensuse.org/request/show/1135432 Factory / cJSON
We are not really tracking Leap, are we?
This is an autogenerated message for OBS integration: This bug (1218098) was mentioned in https://build.opensuse.org/request/show/1176530 Backports:SLE-15-SP5 / cJSON
openSUSE-SU-2024:0139-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1218098,1218099,1223420 CVE References: CVE-2023-50471,CVE-2023-50472,CVE-2024-31755 JIRA References: Sources used: openSUSE Backports SLE-15-SP5 (src): cJSON-1.7.18-bp155.3.3.1