Skip to content

[develop] Backport CVE-2019-1010239: NULL deref on cJSON_GetObjectItemCaseSensitive(array)#1024

Open
dkgkdfg65 wants to merge 1 commit into
DaveGamble:developfrom
dkgkdfg65:nonbsp/backport/cve-2019-1010239-develop
Open

[develop] Backport CVE-2019-1010239: NULL deref on cJSON_GetObjectItemCaseSensitive(array)#1024
dkgkdfg65 wants to merge 1 commit into
DaveGamble:developfrom
dkgkdfg65:nonbsp/backport/cve-2019-1010239-develop

Conversation

@dkgkdfg65
Copy link
Copy Markdown

backports be749d7efa7c to develop for CVE-2019-1010239 (refs #1023).

see #1023 for Docker A/B evidence — calling cJSON_GetObjectItemCaseSensitive() on an array currently crashes (exit 139, SIGSEGV in strcmp(name, NULL)); post-fix returns NULL gracefully (exit 0).

upstream: be749d7efa7c
CVE: https://nvd.nist.gov/vuln/detail/CVE-2019-1010239

clean cherry-pick with -x. no local test run.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants