CVE-2023-33460
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jun 6, 2023
Updated: Jan 8, 2025
CWE ID 401
Summary
CVE-2023-33460 is a memory leak vulnerability affecting yajl version 2.1.0. The issue is linked to the yajl_tree_parse function, which, when used, can lead to an out-of-memory condition in servers, ultimately causing them to crash. This vulnerability could potentially be exploited by attackers to cause denial-of-service (DoS) attacks or gain unauthorized access to affected systems. System administrators are advised to upgrade to a patched version of yajl to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Fedora Operating System
- Debian
Affected Vendors
- Debian
- Fedora Project