Skip to content

Commit

Permalink
fix: fix NULL valuestring error
Browse files Browse the repository at this point in the history
Fix NULL valuestring problem in cJSON_SetValuestring.
This fixes DaveGamble#839 and CVE-2024-31755
Related issue DaveGamble#845
  • Loading branch information
Alanscut committed Apr 28, 2024
1 parent f8b407e commit a193d24
Showing 1 changed file with 7 additions and 1 deletion.
8 changes: 7 additions & 1 deletion cJSON.c
Original file line number Diff line number Diff line change
Expand Up @@ -406,10 +406,16 @@ CJSON_PUBLIC(char*) cJSON_SetValuestring(cJSON *object, const char *valuestring)
return NULL;
}
/* return NULL if the object is corrupted */
if (object->valuestring == NULL || valuestring == NULL)
if (object->valuestring == NULL)
{
return NULL;
}
/* NULL valuestring causes error with strlen and should be treated separately */
if (valuestring == NULL)
{
object->valuestring = NULL;
return NULL;
}
if (strlen(valuestring) <= strlen(object->valuestring))
{
strcpy(object->valuestring, valuestring);
Expand Down

0 comments on commit a193d24

Please sign in to comment.