[esnet/iperf] 2669b2: Add a variant of cJSON_GetObjectItem that does typ...

0 views
Skip to first unread message

swlars

unread,
Dec 13, 2024, 2:08:44 PM12/13/24
to iper...@googlegroups.com
Branch: refs/heads/master
Home: https://github.com/esnet/iperf
Commit: 2669b28533aab508b226774e71133535e1da6523
https://github.com/esnet/iperf/commit/2669b28533aab508b226774e71133535e1da6523
Author: Sarah Larsen <swla...@es.net>
Date: 2024-12-13 (Fri, 13 Dec 2024)

Changed paths:
M src/iperf_api.c
M src/iperf_util.c
M src/iperf_util.h

Log Message:
-----------
Add a variant of cJSON_GetObjectItem that does type-checking.

This avoids a potential server crash with malformed iperf3
parameter sets. (CVE-2024-53580)

Vulnerability report submitted by Leonid Krolle Bi.Zone.

Original version of fix by @dopheide-esnet.



To unsubscribe from these emails, change your notification settings at https://github.com/esnet/iperf/settings/notifications
Reply all
Reply to author
Forward
0 new messages