Advisories ยป MGASA-2024-0066

Updated yajl packages fix security vulnerabilities

Publication date: 15 Mar 2024
Modification date: 15 Mar 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2017-16516 , CVE-2023-33460

Description

The updated packages fix security vulnerabilities:
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is
supplied to Yajl::Parser.new.parse, the whole ruby process crashes with
a SIGABRT in the yajl_string_decode function in yajl_encode.c. This
results in the whole ruby process terminating and potentially a denial
of service. (CVE-2017-16516)
There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse
function. which will cause out-of-memory in server and cause crash.
(CVE-2023-33460)
                

References

SRPMS

9/core