Logo
vulnerabilityCVE-2023-33460
Name
CVE-2023-33460
Source
NVD ( link)Debian ( link)
Description
There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
yajl
Patched
yajl
Patched

Vulnerability Ratings#


6.5
CVSSv31
6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.1.0
Exploitable
buildroot
master
2.1.0
Exploitable
openwrt
master
2.1.0-r4
Patched
openwrt
openwrt-25.12
2.1.0-r4
Patched
yocto
master
2.1.0
Patched
yocto
scarthgap
1.0.12
Patched

Resolved with patches#


yajl (openwrt:master)

#
Title
Author
Resolve
1
Fix for CVE-2023-33460a
Like Ma <likemartinma@gmail.com>
CVE-2023-33460

yajl (openwrt:openwrt-25.12)

#
Title
Author
Resolve
1
Fix for CVE-2023-33460a
Like Ma <likemartinma@gmail.com>
CVE-2023-33460

yajl (yocto:kirkstone)

#
Title
Author
Resolve
1
fix memory leaks
"zhang.jiujiu" <282627424@qq.com>
CVE-2023-33460

yajl (yocto:kirkstone)

#
Title
Author
Resolve
1
fix memory leaks
"zhang.jiujiu" <282627424@qq.com>
CVE-2023-33460

yajl (yocto:master)

#
Title
Author
Resolve
1
Patch #1
Ross Burton <ross.burton@arm.com>
CVE-2023-33460

yajl (yocto:master)

#
Title
Author
Resolve
1
Patch #1
Ross Burton <ross.burton@arm.com>
CVE-2023-33460

yajl (yocto:scarthgap)

#
Title
Author
Resolve
1
Patch #1
Ross Burton <ross.burton@arm.com>
CVE-2023-33460

yajl (yocto:scarthgap)

#
Title
Author
Resolve
1
Patch #1
Ross Burton <ross.burton@arm.com>
CVE-2023-33460