PT-2023-6791 · Yajl+11 · Yajl+11

Notmebutwind

·

Published

2023-05-08

·

Updated

2026-03-29

·

CVE-2023-33460

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions yajl version 2.1.0
Description The issue is related to a memory leak caused by the use of the yajl tree parse function in the yajl library. This can lead to out-of-memory conditions in servers, resulting in crashes. The vulnerability can be exploited by remote attackers to cause a denial of service.
Recommendations For yajl version 2.1.0, consider disabling the yajl tree parse function as a temporary workaround until a patch is available. Restricting the use of this function can help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Leak

Weakness Enumeration

Related Identifiers

ALSA-2023:6551
ALSA-2023:7057
ALT-PU-2023-1991
ALT-PU-2023-2005
ALT-PU-2023-2007
ALT-PU-2023-2013
ALT-PU-2023-4612
AZL-27143
AZL-35363
BDU:2023-07652
CESA-2023_7057
CVE-2023-33460
DLA-3478-1
DLA-3492-1
DLA-3516-1
INFSA-2023_6551
MGASA-2024-0066
OPENSUSE-SU-2023_3301-1
OPENSUSE-SU-2024:13057-1
RHSA-2023:6551
RHSA-2023:7057
RHSA-2023_6551
RHSA-2023_7057
RHSA-2024:2063
RHSA-2024:2580
RLSA-2023:6551
RLSA-2023:7057
ROSA-SA-2024-2478
RSEC-2023-3
SUSE-SU-2023:3301-1
SUSE-SU-2023_3301-1
USN-6233-1
USN-6233-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Yajl