yajl-ruby
Ruby C bindings to the excellent Yajl JSON stream-based parser library.
Activity
- Latest release
- 4y ago
- Total releases
- 44
- Cadence
- ~22 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Jun 18, 2009
| Version | Released | |
|---|---|---|
1.4.3
patch
| ||
1.4.2
patch
1 CVE
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.4.1
patch
1 CVE
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.4.0
minor
1 CVE
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.3
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.3.1
patch
1 CVE
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.2
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.3.0
minor
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.1
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.0
minor
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.0
minor
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.0
major
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.8.3
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.8.2
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.8.1
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.8.0
minor
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.7.9
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.7.8
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.7.7
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.7.6
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.7.5
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.7.4
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.7.3
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.7.2
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.7.1
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.7.0
minor
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.9
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.8
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.7
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.6
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.5
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.4
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.2
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.3
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.1
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.6.0
minor
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.5.12
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.5.11
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.5.10
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.5.9
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.5.8
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.5.7
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.5.6
patch
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.5.5
initial
2 CVEs
CVE-2022-24795
GHSA-jj47-x69x-mxrm
Apr 05, 2022
Buffer Overflow in yajl-ruby
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3 The 1.x branch and the 2.x branch of yajl contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. DetailsThe reallocation logic at yajl_buf.c#L64 may result in the These integers are declared as Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. ImpactWe rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely. PatchesPatched in yajl-ruby 1.4.3 WorkaroundsAvoid passing large inputs to YAJL Referenceshttps://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64 For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 31 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
Fixed in
1.4.3
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-16516
GHSA-wwh7-4jw9-33x6
Nov 28, 2017
yajl-ruby gem Denial of Service vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Affected versions
0.5.10
0.5.11
0.5.12
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.2
0.6.3
+ 27 more Show less
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.3
1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.3.0
Fixed in
1.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev |