VDB
Sign up
HIGH7.5

GHSA-wwh7-4jw9-33x6

yajl-ruby gem Denial of Service vulnerability

Quick fix

GHSA-wwh7-4jw9-33x6 — yajl-ruby: upgrade to the fixed version with the command below.

bundle update yajl-ruby

Details

In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to `Yajl::Parser.new.parse`, the whole ruby process crashes with a SIGABRT in the `yajl_string_decode` function in `yajl_encode.c`. This results in the whole ruby process terminating and potentially a denial of service.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/yajl-ruby
Introduced in: 0Fixed in: 1.3.1
Fixbundle update yajl-ruby

References