Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-33460

Опубликовано: 06 июн. 2023
Источник: debian
EPSS Низкий

Описание

There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
yajlfixed2.1.0-5package
yajlfixed2.1.0-3+deb12u2bookwormpackage
yajlfixed2.1.0-3+deb11u2bullseyepackage
epics-basenot-affectedpackage
r-cran-jsonlitefixed1.8.8+dfsg-1package
r-cran-jsonliteno-dsabookwormpackage
r-cran-jsonliteno-dsabullseyepackage
r-cran-jsonlitepostponedbusterpackage
ruby-yajlnot-affectedpackage

Примечания

  • https://github.com/lloyd/yajl/issues/250

  • Introduced with: https://github.com/lloyd/yajl/commit/cfa9f8fcb12d80dd5ebf94f5e6a607aab4d225fb (2.0.0)

  • The original fix uploaded as 2.1.0-3.1 was incomplete.

  • ruby-yajl embeds yajl version 1.0.12 (https://github.com/brianmario/yajl-ruby/blob/master/ext/yajl/api/yajl_version.h)

  • r-cran-jsonlite: https://github.com/jeroen/jsonlite/issues/426

  • r-cran-jsonlite: https://github.com/jeroen/jsonlite/pull/421

  • r-cran-jsonlite: https://github.com/jeroen/jsonlite/commit/e8965dfead9f270ff8d7bb3029e86dee866d407d (v1.8.8)

EPSS

Процентиль: 32%
0.00119
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 лет назад

There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.

CVSS3: 6.5
redhat
около 2 лет назад

There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.

CVSS3: 6.5
nvd
около 2 лет назад

There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.

CVSS3: 6.5
msrc
около 2 лет назад

Описание отсутствует

suse-cvrf
почти 2 года назад

Security update for libyajl

EPSS

Процентиль: 32%
0.00119
Низкий