CVE-2023-33460

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jun 6, 2023
Updated: Jan 8, 2025
CWE ID 401

Summary

CVE-2023-33460 is a memory leak vulnerability affecting yajl version 2.1.0. The issue is linked to the yajl_tree_parse function, which, when used, can lead to an out-of-memory condition in servers, ultimately causing them to crash. This vulnerability could potentially be exploited by attackers to cause denial-of-service (DoS) attacks or gain unauthorized access to affected systems. System administrators are advised to upgrade to a patched version of yajl to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Fedora Operating System
  • Debian

Affected Vendors

  • Debian
  • Fedora Project