From 94117a5d239bd7686b485e2f820e79a522f0fd19 Mon Sep 17 00:00:00 2001 From: Max Bruckner Date: Wed, 15 Feb 2017 15:37:38 +0100 Subject: [PATCH] Fix #105, double free when parse_string fails This fixes a double free that happens when calling cJSON_Delete on an item that has been used by parse_string and it failed parsing the string. The double free happens, because parse_string frees an alias of item->valuestring, but doesn't set item->valuestring to NULL. --- cJSON.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/cJSON.c b/cJSON.c index b16abae..7c0d9f3 100644 --- a/cJSON.c +++ b/cJSON.c @@ -468,7 +468,6 @@ static const unsigned char *parse_string(cJSON *item, const unsigned char *str, { goto fail; } - item->valuestring = (char*)out; /* assign here so out will be deleted during cJSON_Delete() later */ item->type = cJSON_String; ptr = str + 1; @@ -608,6 +607,8 @@ static const unsigned char *parse_string(cJSON *item, const unsigned char *str, ptr++; } + item->valuestring = (char*)out; + return ptr; fail: