[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2017-16516 -- ruby-yajl

ID: oval:org.secpod.oval:def:2001040Date: (C)2019-06-03   (M)2024-01-16
Class: VULNERABILITYFamily: unix




In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process terminating and potentially a denial of service.

Platform:
Debian 8.x
Debian 9.x
Product:
ruby-yajl
Reference:
CVE-2017-16516
CVE    1
CVE-2017-16516
CPE    3
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x
cpe:/a:yajl-ruby_project:ruby-yajl

© SecPod Technologies