HIGH7.5
GHSA-wwh7-4jw9-33x6
yajl-ruby gem Denial of Service vulnerability
Quick fix
GHSA-wwh7-4jw9-33x6 — yajl-ruby: upgrade to the fixed version with the command below.
bundle update yajl-rubyDetails
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to `Yajl::Parser.new.parse`, the whole ruby process crashes with a SIGABRT in the `yajl_string_decode` function in `yajl_encode.c`. This results in the whole ruby process terminating and potentially a denial of service.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-16516[ADVISORY]
- https://github.com/brianmario/yajl-ruby/issues/176[WEB]
- https://github.com/brianmario/yajl-ruby/pull/178[WEB]
- https://github.com/github/advisory-database/pull/2158[WEB]
- https://github.com/brianmario/yajl-ruby/commit/a8ca8f476655adaa187eedc60bdc770fff3c51ce[WEB]
- https://github.com/brianmario/yajl-ruby[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/yajl-ruby/CVE-2017-16516.yml[WEB]
- https://lists.debian.org/debian-lts-announce/2017/11/msg00010.html[WEB]
- https://lists.debian.org/debian-lts-announce/2023/07/msg00013.html[WEB]
- https://lists.debian.org/debian-lts-announce/2023/08/msg00003.html[WEB]
- https://rubygems.org/gems/yajl-ruby[WEB]