CVE-2017-16516
published 2017-11-03CVE-2017-16516: In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.80%
88.9th percentile
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process terminating and potentially a denial of service.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| burp_project | burp | >= 0 < 3.1.4-2 | 3.1.4-2 |
| burp_project | burp | >= 0 < 3.1.4-2 | 3.1.4-2 |
| debian | burp | < burp 3.1.4-2 (forky) | burp 3.1.4-2 (forky) |
| debian | debian_linux | — | — |
| debian | epics-base | < burp 3.1.4-2 (forky) | burp 3.1.4-2 (forky) |
| debian | r-cran-jsonlite | < burp 3.1.4-2 (forky) | burp 3.1.4-2 (forky) |
| debian | ruby-yajl | < burp 3.1.4-2 (forky) | burp 3.1.4-2 (forky) |
| debian | xqilla | < burp 3.1.4-2 (forky) | burp 3.1.4-2 (forky) |
| debian | yajl | < burp 3.1.4-2 (forky) | burp 3.1.4-2 (forky) |
| yajl-ruby_project | yajl-ruby | — | — |
| yajl-ruby_project | yajl-ruby | >= 0 < 1.3.1 | 1.3.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
yajl vulnerabilities
osv·2023-12-14·CVSS 7.5
[HIGH] yajl vulnerabilities
yajl vulnerabilities
USN-6233-1 fixed vulnerabilities in YAJL. This update provides the
corresponding updates for Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu
23.04.
Original advisory details:
It was discovered that YAJL was not properly performing bounds checks when
decoding a string with escape sequences. If a user or automated system
using YAJL were tricked into processing specially crafted input, an
attacker could possibly use this issue to cause a denial of service
(application abort). (CVE-2017-16516)
It was discovered that YAJL was not properly handling memory allocation
when dealing with large inputs, which could lead to heap memory
corruption. If a user or automated system using YAJL were tricked into
running a specially crafted large input, an attacker could possibly use
th
OSV
yajl vulnerabilities
osv·2023-07-18·CVSS 7.5
CVE-2017-16516 [HIGH] yajl vulnerabilities
yajl vulnerabilities
It was discovered that YAJL was not properly performing bounds checks when
decoding a string with escape sequences. If a user or automated system
using YAJL were tricked into processing specially crafted input, an
attacker could possibly use this issue to cause a denial of service
(application abort). (CVE-2017-16516)
It was discovered that YAJL was not properly handling memory allocation
when dealing with large inputs, which could lead to heap memory
corruption. If a user or automated system using YAJL were tricked into
running a specially crafted large input, an attacker could possibly use
this issue to cause a denial of service. (CVE-2022-24795)
It was discovered that memory leaks existed in one of the YAJL parsing
functions. An attacker could possibly use this i
GHSA
yajl-ruby gem Denial of Service vulnerability
ghsa·2017-11-28
CVE-2017-16516 [HIGH] CWE-134 yajl-ruby gem Denial of Service vulnerability
yajl-ruby gem Denial of Service vulnerability
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to `Yajl::Parser.new.parse`, the whole ruby process crashes with a SIGABRT in the `yajl_string_decode` function in `yajl_encode.c`. This results in the whole ruby process terminating and potentially a denial of service.
OSV
yajl-ruby gem Denial of Service vulnerability
osv·2017-11-28
CVE-2017-16516 [HIGH] yajl-ruby gem Denial of Service vulnerability
yajl-ruby gem Denial of Service vulnerability
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to `Yajl::Parser.new.parse`, the whole ruby process crashes with a SIGABRT in the `yajl_string_decode` function in `yajl_encode.c`. This results in the whole ruby process terminating and potentially a denial of service.
OSV
CVE-2017-16516: In the yajl-ruby gem 1
osv·2017-11-03·CVSS 7.5
CVE-2017-16516 [HIGH] CVE-2017-16516: In the yajl-ruby gem 1
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process terminating and potentially a denial of service.
Ubuntu
YAJL vulnerabilities
vendor_ubuntu·2023-12-14·CVSS 7.5
CVE-2023-33460 [HIGH] YAJL vulnerabilities
Title: YAJL vulnerabilities
Summary: Several security issues were fixed in YAJL.
USN-6233-1 fixed vulnerabilities in YAJL. This update provides the
corresponding updates for Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu
23.04.
Original advisory details:
It was discovered that YAJL was not properly performing bounds checks when
decoding a string with escape sequences. If a user or automated system
using YAJL were tricked into processing specially crafted input, an
attacker could possibly use this issue to cause a denial of service
(application abort). (CVE-2017-16516)
It was discovered that YAJL was not properly handling memory allocation
when dealing with large inputs, which could lead to heap memory
corruption. If a user or automated system using YAJL were tricked into
running a spe
Ubuntu
YAJL vulnerabilities
vendor_ubuntu·2023-07-18·CVSS 7.5
CVE-2023-33460 [HIGH] YAJL vulnerabilities
Title: YAJL vulnerabilities
Summary: Several security issues were fixed in YAJL.
It was discovered that YAJL was not properly performing bounds checks when
decoding a string with escape sequences. If a user or automated system
using YAJL were tricked into processing specially crafted input, an
attacker could possibly use this issue to cause a denial of service
(application abort). (CVE-2017-16516)
It was discovered that YAJL was not properly handling memory allocation
when dealing with large inputs, which could lead to heap memory
corruption. If a user or automated system using YAJL were tricked into
running a specially crafted large input, an attacker could possibly use
this issue to cause a denial of service. (CVE-2022-24795)
It was discovered that memory leaks existed in one of the
Red Hat
rubygem-yajl-ruby: Yajl:: Parser.new.parse incorrect parsing
vendor_redhat·2017-11-02·CVSS 7.5
CVE-2017-16516 [HIGH] CWE-20 rubygem-yajl-ruby: Yajl:: Parser.new.parse incorrect parsing
rubygem-yajl-ruby: Yajl:: Parser.new.parse incorrect parsing
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process terminating and potentially a denial of service.
Package: rubygem-yajl-ruby (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools) - Will not fix
Package: rubygem-yajl-ruby (Red Hat OpenShift Enterprise 3) - Not affected
Package: rubygem-yajl-ruby (Red Hat OpenStack Platform 10 (Newton) Operational Tools) - Will not fix
Package: rubygem-yajl-ruby (Red Hat OpenStack Platform 11 (Ocata) Operational Tools) - Will not fix
Package: rubygem-yajl-ruby (Red Hat OpenStack Platform
Debian
CVE-2017-16516: burp - In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yaj...
vendor_debian·2017·CVSS 7.5
CVE-2017-16516 [HIGH] CVE-2017-16516: burp - In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yaj...
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process terminating and potentially a denial of service.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.1.4-2)
sid: resolved (fixed in 3.1.4-2)
trixie: resolved (fixed in 3.1.4-2)
No detection rules found.
No public exploits indexed.
https://github.com/brianmario/yajl-ruby/issues/176https://lists.debian.org/debian-lts-announce/2017/11/msg00010.htmlhttps://lists.debian.org/debian-lts-announce/2023/07/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2023/08/msg00003.htmlhttps://rubygems.org/gems/yajl-rubyhttps://github.com/brianmario/yajl-ruby/issues/176https://lists.debian.org/debian-lts-announce/2017/11/msg00010.htmlhttps://lists.debian.org/debian-lts-announce/2023/07/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2023/08/msg00003.htmlhttps://rubygems.org/gems/yajl-ruby
2017-11-03
Published