parse_string in cJSON before 1.7.18 has a heap-based...
Low severity
Unreviewed
Published
May 23, 2025
to the GitHub Advisory Database
•
Updated May 23, 2025
Description
Published by the National Vulnerability Database
May 23, 2025
Published to the GitHub Advisory Database
May 23, 2025
Last updated
May 23, 2025
parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.
References