[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2017-16516 -- ruby-yajl, libyajl-dev

ID: oval:org.secpod.oval:def:1901789Date: (C)2019-06-03   (M)2024-01-16
Class: VULNERABILITYFamily: unix




In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process terminating and potentially a denial of service.

Platform:
Ubuntu 16.04
Ubuntu 18.10
Ubuntu 14.04
Ubuntu 18.04
Product:
ruby-yajl
libyajl-dev
Reference:
CVE-2017-16516
CVE    1
CVE-2017-16516
CPE    6
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/o:ubuntu:ubuntu_linux:18.04
cpe:/a:lloyd:libyajl-dev
cpe:/o:ubuntu:ubuntu_linux:14.04
...

© SecPod Technologies