There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.
References
| Link | Resource |
|---|---|
| https://github.com/lloyd/yajl/issues/250 | Exploit Issue Tracking Patch Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2023/07/msg00000.html | Mailing List Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2023/07/msg00013.html | Mailing List Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KLE3C4CECEJ4EUYI56KXI6OWACWXX7WN/ | Mailing List |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IBUUHG27RM4ROEYKMVRROR27AX6R63MB/ | Mailing List |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YO32YDJ74DADC7CMJNLSLBVWN5EXGF5J/ | Mailing List |
| https://lists.debian.org/debian-lts-announce/2023/08/msg00003.html |
Information
Published : 2023-06-06 12:15
Updated : 2023-08-05 19:15
NVD link : CVE-2023-33460
Mitre link : CVE-2023-33460
JSON object : View
Products Affected
fedoraproject
- fedora
debian
- debian_linux
yajl_project
- yajl
CWE
CWE-401
Missing Release of Memory after Effective Lifetime
