There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.
References
Configurations
History
21 Nov 2024, 08:05
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/lloyd/yajl/issues/250 - Exploit, Issue Tracking, Patch, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2023/07/msg00000.html - Mailing List, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2023/07/msg00013.html - Mailing List, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2023/08/msg00003.html - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IBUUHG27RM4ROEYKMVRROR27AX6R63MB/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KLE3C4CECEJ4EUYI56KXI6OWACWXX7WN/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YO32YDJ74DADC7CMJNLSLBVWN5EXGF5J/ - |
07 Nov 2023, 04:14
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
05 Aug 2023, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
02 Aug 2023, 16:45
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
|
References | (MLIST) https://lists.debian.org/debian-lts-announce/2023/07/msg00000.html - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.debian.org/debian-lts-announce/2023/07/msg00013.html - Mailing List, Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YO32YDJ74DADC7CMJNLSLBVWN5EXGF5J/ - Mailing List | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KLE3C4CECEJ4EUYI56KXI6OWACWXX7WN/ - Mailing List | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IBUUHG27RM4ROEYKMVRROR27AX6R63MB/ - Mailing List | |
First Time |
Debian
Debian debian Linux Fedoraproject fedora Fedoraproject |
27 Jul 2023, 05:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
21 Jul 2023, 04:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
16 Jul 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
11 Jul 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
02 Jul 2023, 13:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
12 Jun 2023, 14:27
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-401 | |
References | (MISC) https://github.com/lloyd/yajl/issues/250 - Exploit, Issue Tracking, Patch, Third Party Advisory | |
CPE | cpe:2.3:a:yajl_project:yajl:2.1.0:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
First Time |
Yajl Project
Yajl Project yajl |
06 Jun 2023, 12:50
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-06 12:15
Updated : 2024-11-21 08:05
NVD link : CVE-2023-33460
Mitre link : CVE-2023-33460
CVE.ORG link : CVE-2023-33460
JSON object : View
Products Affected
debian
- debian_linux
yajl_project
- yajl
fedoraproject
- fedora
CWE
CWE-401
Missing Release of Memory after Effective Lifetime