From 449538348ebc941bd7a2ebde3e4e691daca45a91 Mon Sep 17 00:00:00 2001 From: Fabrice Fontaine Date: Tue, 26 Dec 2023 12:34:28 +0100 Subject: [PATCH] package/cjson: security bump to version 1.7.17 - Fix null reference in cJSON_SetValuestring (CVE-2023-50472) - Fix null reference in cJSON_InsertItemInArray (CVE-2023-50471) https://github.com/DaveGamble/cJSON/releases/tag/v1.7.17 Signed-off-by: Fabrice Fontaine Signed-off-by: Thomas Petazzoni --- package/cjson/cjson.hash | 2 +- package/cjson/cjson.mk | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/package/cjson/cjson.hash b/package/cjson/cjson.hash index 74844d6aa6..305dc0d7b8 100644 --- a/package/cjson/cjson.hash +++ b/package/cjson/cjson.hash @@ -1,3 +1,3 @@ # Locally computed: -sha256 451131a92c55efc5457276807fc0c4c2c2707c9ee96ef90c47d68852d5384c6c cjson-1.7.16.tar.gz +sha256 c91d1eeb7175c50d49f6ba2a25e69b46bd05cffb798382c19bfb202e467ec51c cjson-1.7.17.tar.gz sha256 a36dda207c36db5818729c54e7ad4e8b0c6fba847491ba64f372c1a2037b6d5c LICENSE diff --git a/package/cjson/cjson.mk b/package/cjson/cjson.mk index 7ed732ac90..f699c160ef 100644 --- a/package/cjson/cjson.mk +++ b/package/cjson/cjson.mk @@ -4,7 +4,7 @@ # ################################################################################ -CJSON_VERSION = 1.7.16 +CJSON_VERSION = 1.7.17 CJSON_SITE = $(call github,DaveGamble,cjson,v$(CJSON_VERSION)) CJSON_INSTALL_STAGING = YES CJSON_LICENSE = MIT