USN-6233-1
Dashboard / Vulnerabilities / USN-6233-1
USN-6233-1
Summary: yajl vulnerabilities
Details: It was discovered that YAJL was not properly performing bounds checks when decoding a string with escape sequences. If a user or automated system using YAJL were tricked into processing specially crafted input, an attacker could possibly use this issue to cause a denial of service (application abort). (CVE-2017-16516) It was discovered that YAJL was not properly handling memory allocation when dealing with large inputs, which could lead to heap memory corruption. If a user or automated system using YAJL were tricked into running a specially crafted large input, an attacker could possibly use this issue to cause a denial of service. (CVE-2022-24795) It was discovered that memory leaks existed in one of the YAJL parsing functions. An attacker could possibly use this issue to cause a denial of service (memory exhaustion). (CVE-2023-33460)
References: https://ubuntu.com/security/notices/USN-6233-1, https://ubuntu.com/security/CVE-2017-16516, https://ubuntu.com/security/CVE-2022-24795, https://ubuntu.com/security/CVE-2023-33460
Affected packages
Package
Name: yajl
Purl: pkg:deb/ubuntu/yajl?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
