USN-6233-1: YAJL vulnerabilities
It was discovered that YAJL was not properly performing bounds checks when decoding a string with escape sequences. If a user or automated system using YAJL were tricked into processing specially crafted input, an attacker could possibly use this issue to cause a denial of service (application abort). (CVE-2017-16516) It was discovered that YAJL was not properly handling memory allocation when dealing with large inputs, which could lead to heap memory corruption. If a user or automated system using YAJL were tricked into running a specially crafted large input, an attacker could possibly use this issue to cause a denial of service. (CVE-2022-24795) It was discovered that memory leaks existed in one of the YAJL parsing functions. An attacker could possibly use this issue to cause a denial of service (memory exhaustion). (CVE-2023-33460)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6233-1?
The severity of USN-6233-1 is considered high due to the potential for denial of service.
How do I fix USN-6233-1?
To fix USN-6233-1, upgrade the libyajl2 package to the appropriate version for your Ubuntu release.
What causes the vulnerability in USN-6233-1?
The vulnerability in USN-6233-1 is caused by improper bounds checking when decoding escape sequences in strings.
Which versions of Ubuntu are affected by USN-6233-1?
USN-6233-1 affects Ubuntu versions 14.04, 16.04, and 18.04 that use the vulnerable libyajl2 package.
Can the vulnerability in USN-6233-1 be exploited remotely?
Yes, if an attacker can trick a user or automated system into processing specially crafted input, the vulnerability can be exploited.