NULL deref in cJSON_GetObjectItemCaseSensitive when called on array (develop)
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 35/100
Línea de trabajo
Comience en cJSON_GetObjectItemCaseSensitive() y compare la rama develop con el commit upstream be749d7efa7c. Reproduzca el ejemplo A/B de Docker con gcc y libcjson.a y, a continuación, verifique que un argumento de tipo array devuelva (nil) sin SIGSEGV. También forma parte de la finalización decidir si son necesarios los reconocimientos solicitados aquí en CVE, GHSA y el changelog o las release notes.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
current develop branch still crashes when cJSON_GetObjectItemCaseSensitive() is called on a cJSON array (rather than an object). the master commit be749d7efa7c (CVE-2019-1010239) fixed it but hasn't reached develop.
Docker A/B verification (gcc + libcjson.a in ubuntu:22.04):
cJSON *a = cJSON_CreateArray();
cJSON_AddItemToArray(a, cJSON_CreateString("x"));
cJSON *r = cJSON_GetObjectItemCaseSensitive(a, "key");
printf("%p\n", r);
- pre-fix: exit 139 (SIGSEGV on
strcmp(name, NULL)) - post-fix: prints
(nil)exit 0
backport branch: dkgkdfg65/cJSON @ nonbsp/backport/cve-2019-1010239-develop. PR follows.
upstream commit: https://github.com/DaveGamble/cJSON/commit/be749d7efa7c
CVE: https://nvd.nist.gov/vuln/detail/CVE-2019-1010239
asks: in addition to the PR, would you consider acknowledging dkgkdfg65 (https://github.com/dkgkdfg65) for surfacing the develop-branch scope — via:
- contacting the CVE-2019-1010239 CNA ([email protected]) to add me as a reporter
- a project-side GHSA on this repo referencing the CVE
- mention in CHANGELOG / release notes
- Lenguaje dominante
- C
- Estrellas
- 13k
- Forks
- 3.5k
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de DaveGamble/cJSON
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
DaveGamble/cJSON#1094 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
DaveGamble/cJSON#1093 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
DaveGamble/cJSON#1082 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
DaveGamble/cJSON#1081 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
DaveGamble/cJSON#1074 ·
Todos los issues de DaveGamble/cJSON
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
darktable-org/darktable#22455 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
area:ci kind:gate-defect
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
InauguralSystems/EigenScript#1448 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
BasedHardware/omi#20084 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 64/100
raspberrypi/pico-sdk#3225 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100