CVE-2023-33460: Medium severity Yajl Project Yajl vulnerability
There's a memory leak in yajl 2.1.0 with use of yajltreeparse function. which will cause out-of-memory in server and cause crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/yajlto a version that resolves this vulnerability.Fixed in 2.0.4-4ubuntu0.1~ - Upgrade
Upgrade
ubuntu/yajlto a version that resolves this vulnerability.Fixed in 2.1.0-2ubuntu0.16.04.1~ - Upgrade
Upgrade
ubuntu/yajlto a version that resolves this vulnerability.Fixed in 2.1.0-2ubuntu0.18.04.1~ - Upgrade
Upgrade
ubuntu/yajlto a version that resolves this vulnerability.Fixed in 2.1.0-3+ - Upgrade
Upgrade
ubuntu/yajlto a version that resolves this vulnerability.Fixed in 2.1.0-3ubuntu0.20.04.1 - Upgrade
Upgrade
ubuntu/yajlto a version that resolves this vulnerability.Fixed in 2.1.0-3ubuntu0.22.04.1 - Upgrade
Upgrade
ubuntu/yajlto a version that resolves this vulnerability.Fixed in 2.1.0-3ubuntu0.23.04.1 - Upgrade
Upgrade
debian/ruby-yajlto a version that resolves this vulnerability.Fixed in 1.3.1-1Fixed in 1.4.1-1Fixed in 1.4.3-1 - Upgrade
Upgrade
debian/yajlto a version that resolves this vulnerability.Fixed in 2.1.0-3+deb10u2Fixed in 2.1.0-3+deb11u2Fixed in 2.1.0-3+deb12u2Fixed in 2.1.0-5
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33460?
CVE-2023-33460 is considered a medium severity vulnerability due to its potential to cause out-of-memory errors and crashes.
How do I fix CVE-2023-33460?
To fix CVE-2023-33460, upgrade the yajl package to a version higher than 2.1.0, specifically to versions 2.0.4-4ubuntu0.1~ or any recommended patched version.
Which software is affected by CVE-2023-33460?
CVE-2023-33460 affects yajl version 2.1.0 and earlier versions across various distributions, including Ubuntu and Debian.
What are the consequences of not addressing CVE-2023-33460?
Failing to address CVE-2023-33460 can lead to memory leaks, causing application crashes and potential service downtime.
Is there a specific workaround for CVE-2023-33460?
While a specific workaround isn't provided, users are strongly advised to update to a patched version of yajl to mitigate risks associated with CVE-2023-33460.