cJSON aims to be the dumbest possible parser that you can get your job done with. It's a single file of C, and a single header file. %package devel Summary: Development files for cJSON Requires: = - %description devel The cjson-devel package contains libraries and header files for developing applications that use cJSON. %prep %autosetup -n cJSON- -p1
Security Fix(es):
cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decodearrayindexfrompointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.(CVE-2025-57052)
{ "severity": "Critical" }
{ "aarch64": [ "cjson-1.7.15-11.oe2403.aarch64.rpm", "cjson-debuginfo-1.7.15-11.oe2403.aarch64.rpm", "cjson-debugsource-1.7.15-11.oe2403.aarch64.rpm", "cjson-devel-1.7.15-11.oe2403.aarch64.rpm" ], "src": [ "cjson-1.7.15-11.oe2403.src.rpm" ], "x86_64": [ "cjson-1.7.15-11.oe2403.x86_64.rpm", "cjson-debuginfo-1.7.15-11.oe2403.x86_64.rpm", "cjson-debugsource-1.7.15-11.oe2403.x86_64.rpm", "cjson-devel-1.7.15-11.oe2403.x86_64.rpm" ] }