RHSA-2024:2063: Moderate: yajl security update
Moderate: yajl security update
Other sources
Yet Another JSON Library (YAJL) is a small event-driven (SAX-style) JSON parser written in ANSI C, and a small validating JSON generator.Security Fix(es): yajl: heap-based buffer overflow when handling large inputs due to an integer overflow (CVE-2022-24795) yajl: Memory leak in yajltreeparse function (CVE-2023-33460) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2063?
The severity of RHSA-2024:2063 is classified as moderate.
How do I fix RHSA-2024:2063?
To fix RHSA-2024:2063, update the yajl package to version 2.1.0-13.el8_6 or later.
What type of vulnerability is identified in RHSA-2024:2063?
RHSA-2024:2063 identifies a heap-based buffer overflow vulnerability due to an integer overflow in yajl.
Which software versions are affected by RHSA-2024:2063?
RHSA-2024:2063 affects versions of the yajl package prior to 2.1.0-13.el8_6.
Is there a specific update for RHSA-2024:2063 available?
Yes, the specific update for RHSA-2024:2063 is yajl version 2.1.0-13.el8_6.