RSEC-2023-3
Dashboard / Vulnerabilities / RSEC-2023-3
Summary: Memory leak vulnerability
Details: The jsonlite R package is exposed to a vulnerability due to its use of yajl library version 2.1.0. The vulnerability originates from the yajl_tree_parse function within yajl. Attackers can exploit this flaw to cause a memory leak, which will result in out-of-memory in server and lead to a crash.
References: https://github.com/jeroen/jsonlite/pull/421, https://nvd.nist.gov/vuln/detail/CVE-2023-33460, https://github.com/lloyd/yajl/issues/250, https://lists.debian.org/debian-lts-announce/2023/07/msg00000.html, https://lists.debian.org/debian-lts-announce/2023/07/msg00013.html, https://lists.fedoraproject.org/archives/list/[email protected]/message/KLE3C4CECEJ4EUYI56KXI6OWACWXX7WN/
Affected packages
Package
Name: jsonlite
Purl: pkg:cran/jsonlite
Affected ranges
Type: ECOSYSTEM
Events:
