rubygem-yajl-ruby: Yajl:: Parser.new.parse incorrect parsing
Published Nov 3, 2017
7.5
HIGHCVSS 3.1
EPSS 3.80%
Description
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process terminating and potentially a denial of service.
Affected products
No data.
Configuration 1
- 1.3.0
Configuration 2
- 7.0
No data.
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools
rubygem-yajl-ruby
Will not fix
Red Hat OpenShift Enterprise 3
rubygem-yajl-ruby
Not affected
Red Hat OpenStack Platform 10 (Newton) Operational Tools
rubygem-yajl-ruby
Will not fix
Red Hat OpenStack Platform 11 (Ocata) Operational Tools
rubygem-yajl-ruby
Will not fix
Red Hat OpenStack Platform 12 (Pike) Operational Tools
rubygem-yajl-ruby
Will not fix
Red Hat OpenStack Platform 13 (Queens) Operational Tools
rubygem-yajl-ruby
Affected
Red Hat OpenStack Platform 8 (Liberty) Operational Tools
rubygem-yajl-ruby
Will not fix
Red Hat OpenStack Platform 9 (Mitaka) Operational Tools
rubygem-yajl-ruby
Will not fix
Red Hat Virtualization 4
rubygem-yajl-ruby
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools | rubygem-yajl-ruby | Will not fix | n/a |
| Red Hat OpenShift Enterprise 3 | rubygem-yajl-ruby | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) Operational Tools | rubygem-yajl-ruby | Will not fix | n/a |
| Red Hat OpenStack Platform 11 (Ocata) Operational Tools | rubygem-yajl-ruby | Will not fix | n/a |
| Red Hat OpenStack Platform 12 (Pike) Operational Tools | rubygem-yajl-ruby | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) Operational Tools | rubygem-yajl-ruby | Affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) Operational Tools | rubygem-yajl-ruby | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | rubygem-yajl-ruby | Will not fix | n/a |
| Red Hat Virtualization 4 | rubygem-yajl-ruby | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (15)
- https://access.redhat.com/security/cve/CVE-2017-16516 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1524439 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-0355 Advisory
- https://github.com/advisories/GHSA-wwh7-4jw9-33x6 Advisory
- https://github.com/brianmario/yajl-ruby/commit/a8ca8f476655adaa187eedc60bdc770fff3c51ce
- https://github.com/brianmario/yajl-ruby/issues/176 ExploitThird Party Advisory
- https://github.com/brianmario/yajl-ruby/pull/178
- https://github.com/github/advisory-database/pull/2158
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/yajl-ruby/CVE-2017-16516.yml
- https://lists.debian.org/debian-lts-announce/2017/11/msg00010.html mailing-listThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/07/msg00013.html mailing-list
- https://lists.debian.org/debian-lts-announce/2023/08/msg00003.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2017-16516
- https://rubygems.org/gems/yajl-ruby Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-16516
Change history (0)
No recorded changes yet.