The updated packages fix security vulnerabilities:
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is
supplied to Yajl::Parser.new.parse, the whole ruby process crashes with
a SIGABRT in the yajl_string_decode function in yajl_encode.c. This
results in the whole ruby process terminating and potentially a denial
of service. (CVE-2017-16516)
There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse
function. which will cause out-of-memory in server and cause crash.
(CVE-2023-33460)
- https://bugs.mageia.org/show_bug.cgi?id=32072
- https://lists.debian.org/debian-lts-announce/2023/07/msg00000.html
- https://lists.debian.org/debian-lts-announce/2023/07/msg00013.html
- https://www.cve.org/CVERecord?id=CVE-2017-16516
- https://www.cve.org/CVERecord?id=CVE-2023-33460
- 9/core/yajl-2.1.0-6.1.mga9
Get the latest Linux and open source security news straight to your inbox.