RHSA-2024:2580: Moderate: yajl security update
Moderate: yajl security update
Other sources
Yet Another JSON Library (YAJL) is a small event-driven (SAX-style) JSON parser written in ANSI C, and a small validating JSON generator.Security Fix(es): yajl: Memory leak in yajltreeparse function (CVE-2023-33460) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2580?
The severity of RHSA-2024:2580 is categorized as moderate.
What is the vulnerability found in RHSA-2024:2580?
RHSA-2024:2580 addresses a memory leak in the yajl_tree_parse function as identified by CVE-2023-33460.
How do I fix RHSA-2024:2580?
To fix RHSA-2024:2580, update the YAJL package to version 2.1.0-12.el8_8 or later.
Which systems are affected by RHSA-2024:2580?
RHSA-2024:2580 affects various versions of the yajl package on Red Hat Enterprise Linux systems.
Is there a workaround for RHSA-2024:2580?
No specific workaround is provided for RHSA-2024:2580; the recommended action is to apply the available updates.