CVE-2023-33460

Summary

CVECVE-2023-33460
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2023-06-06 12:15:00 UTC
Updated2023-11-07 04:14:00 UTC
DescriptionThere's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.

Risk And Classification

Problem Types: CWE-401

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Debian Debian Linux 10.0 All All All
Operating System Fedoraproject Fedora 37 All All All
Operating System Fedoraproject Fedora 38 All All All
Application Yajl Project Yajl 2.1.0 All All All

References

ReferenceSourceLinkTags
[SECURITY] [DLA 3478-1] yajl security update MLIST lists.debian.org
[SECURITY] Fedora 38 Update: R-jsonlite-1.8.5-2.fc38 - package-announce - Fedora Mailing-Lists lists.fedoraproject.org
[SECURITY] Fedora 38 Update: yajl-2.1.0-21.fc38 - package-announce - Fedora Mailing-Lists FEDORA lists.fedoraproject.org
[SECURITY] Fedora 38 Update: yajl-2.1.0-21.fc38 - package-announce - Fedora Mailing-Lists lists.fedoraproject.org
[SECURITY] Fedora 37 Update: yajl-2.1.0-21.fc37 - package-announce - Fedora Mailing-Lists lists.fedoraproject.org
[SECURITY] Fedora 37 Update: yajl-2.1.0-21.fc37 - package-announce - Fedora Mailing-Lists FEDORA lists.fedoraproject.org
[SECURITY] [DLA 3492-1] yajl security update MLIST lists.debian.org
memory leak in yajl_tree_parse function. · Issue #250 · lloyd/yajl · GitHub MISC github.com
[SECURITY] Fedora 38 Update: R-jsonlite-1.8.5-2.fc38 - package-announce - Fedora Mailing-Lists FEDORA lists.fedoraproject.org
[SECURITY] [DLA 3516-1] burp security update MLIST lists.debian.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 161116 Oracle Enterprise Linux Security Update for yajl (ELSA-2023-6551)
  • 161143 Oracle Enterprise Linux Security Update for yajl (ELSA-2023-7057)
  • 199554 Ubuntu Security Notification for YAJL Vulnerabilities (USN-6233-1)
  • 200011 Ubuntu Security Notification for YAJL Vulnerabilities (USN-6233-2)
  • 242290 Red Hat Update for yajl (RHSA-2023:6551)
  • 242408 Red Hat Update for yajl (RHSA-2023:7057)
  • 284318 Fedora Security Update for yajl (FEDORA-2023-00572178e1)
  • 284331 Fedora Security Update for R (FEDORA-2023-0b0bb84049)
  • 284354 Fedora Security Update for yajl (FEDORA-2023-852b377773)
  • 355454 Amazon Linux Security Advisory for yajl : ALAS2023-2023-214
  • 355790 Amazon Linux Security Advisory for yajl : ALAS2-2023-2182
  • 355809 Amazon Linux Security Advisory for yajl : ALAS2023-2023-279
  • 379256 Alibaba Cloud Linux Security Update for yajl (ALINUX3-SA-2024:0007)
  • 6000034 Debian Security Update for burp (DLA 3516-1)
  • 6000066 Debian Security Update for yajl (DLA 3478-1)
  • 754272 SUSE Enterprise Linux Security Update for libyajl (SUSE-SU-2023:3301-1)
  • 907023 Common Base Linux Mariner (CBL-Mariner) Security Update for yajl (27143-1)
  • 907078 Common Base Linux Mariner (CBL-Mariner) Security Update for yajl (27147-1)
  • 941366 AlmaLinux Security Update for yajl (ALSA-2023:6551)
  • 941428 AlmaLinux Security Update for yajl (ALSA-2023:7057)
  • 961079 Rocky Linux Security Update for yajl (RLSA-2023:7057)

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report