CVE-2017-16516
03.11.2017, 15:29
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process terminating and potentially a denial of service.Enginsight
| Vendor | Product | Version |
|---|---|---|
| yajl-ruby_project | yajl-ruby | 1.3.0 |
| debian | debian_linux | 7.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| burp |
| ||||||||||||||
| epics-base |
| ||||||||||||||
| r-cran-jsonlite |
| ||||||||||||||
| ruby-yajl |
| ||||||||||||||
| xqilla |
| ||||||||||||||
| yajl |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ruby-yajl |
| ||||||||||||||||||||||||||||||||||
| yajl |
|
Common Weakness Enumeration
References