]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
json-c: fix CVE-2021-32292
authorAdrian Freihofer <adrian.freihofer@gmail.com>
Tue, 29 Aug 2023 17:00:46 +0000 (19:00 +0200)
committerSteve Sakoman <steve@sakoman.com>
Wed, 30 Aug 2023 16:28:04 +0000 (06:28 -1000)
commita7b93651028b55d71b8db53ea831eee7fd539f33
treed9cb013ae320ff885363037c285fc004995bf14b
parent0619953c9d87ec2dd670dc50f15170e5c42f95c7
json-c: fix CVE-2021-32292

This is a read past end of buffer issue in the json_parse test app,
which can happened with malformed json data. It's not an issue with the
library itself. For what ever reason this CVE has a base score of 9.8.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2021-32292

Upstream issue:
https://github.com/json-c/json-c/issues/654

The CVE is fixed with version 0.16 (which is already in all active
branches of poky).

Signed-off-by: Adrian Freihofer <adrian.freihofer@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-devtools/json-c/json-c/CVE-2021-32292.patch [new file with mode: 0644]
meta/recipes-devtools/json-c/json-c_0.15.bb