Mageia 2024-0156: cjson Security Advisory Updates
Summary
cJSON v1.7.16 was discovered to contain a segmentation violation via the
function cJSON_InsertItemInArray at cJSON.c. (CVE-2023-50471)
cJSON v1.7.16 was discovered to contain a segmentation violation via the
function cJSON_SetValuestring at cJSON.c. (CVE-2023-50472)
References
- https://bugs.mageia.org/show_bug.cgi?id=33133
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-50471
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-50472
Resolution
MGASA-2024-0156 - Updated cjson packages fix security vulnerabilities
SRPMS
- 9/core/cjson-1.7.15-2.1.mga9