|
|
Message-ID: <20260731045907.25edc0c2@del.fritz.box>
Date: Fri, 31 Jul 2026 04:59:07 +0200
From: Jeroen Roovers <jer@...all.nl>
To: Collin Funk <collin.funk1@...il.com>
Cc: oss-security@...ts.openwall.com, Alan Coopersmith
<alan.coopersmith@...cle.com>
Subject: Re: 33 Vulnerabilities in cJSON
On Thu, 30 Jul 2026 12:26:25 -0700
Collin Funk <collin.funk1@...il.com> wrote:
> Alan Coopersmith <alan.coopersmith@...cle.com> writes:
>
> > https://joshua.hu/cjson-json-parser-cve-vulnerabilities says:
> >> cJSON is probably the most widely used JSON parser in the C world.
> >> It’s vendored into ESP-IDF, into a lot of embedded firmware, and
^^^^^^^^^^^^^^^^^
> Does anyone actually use platforms with 32-bit size_t? I guess maybe
> some programs compiled for 32-bit x86 but run on x86_64?
Yes. :-)
Kind regards,
jer
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.