Back to bug 2221249

Who When What Removed Added
Pedro Sampaio 2023-07-07 16:30:01 UTC Depends On 2221250
Pedro Sampaio 2023-07-07 16:36:46 UTC Depends On 2221253, 2221252
Pedro Sampaio 2023-07-07 16:37:13 UTC Blocks 2221254
Daniel Berrangé 2023-07-10 12:02:46 UTC CC adudiak, nweather, stcannon, yguenane
CC berrange
TEJ RATHI 2023-07-12 11:41:54 UTC Depends On 2222241
TEJ RATHI 2023-07-12 11:49:36 UTC Depends On 2222242
TEJ RATHI 2023-07-12 12:04:39 UTC Doc Text The vulnerability was found in yajl library which exists due to memory leak within the yajl_tree_parse() function. A remote attacker could parse malicious JSON input to cause out-of-memory in server which will lead to a crash resulting in denial of service attack.
TEJ RATHI 2023-07-12 12:06:44 UTC Comment 0 updated
TEJ RATHI 2023-07-12 12:08:44 UTC CC trathi
TEJ RATHI 2023-07-12 12:17:29 UTC Alias TRIAGE-CVE-2023-33460 CVE-2023-33460
Summary TRIAGE-CVE-2023-33460 yajl: Memory leak in yajl_tree_parse function CVE-2023-33460 yajl: Memory leak in yajl_tree_parse function
TEJ RATHI 2023-07-12 12:20:35 UTC Alias CVE-2023-33460 TRIAGE-CVE-2023-33460
Summary CVE-2023-33460 yajl: Memory leak in yajl_tree_parse function TRIAGE-CVE-2023-33460 yajl: Memory leak in yajl_tree_parse function
TEJ RATHI 2023-07-12 12:21:12 UTC Alias TRIAGE-CVE-2023-33460 CVE-2023-33460
Summary TRIAGE-CVE-2023-33460 yajl: Memory leak in yajl_tree_parse function CVE-2023-33460 yajl: Memory leak in yajl_tree_parse function
RaTasha Tillery-Smith 2023-07-12 14:04:45 UTC Doc Text The vulnerability was found in yajl library which exists due to memory leak within the yajl_tree_parse() function. A remote attacker could parse malicious JSON input to cause out-of-memory in server which will lead to a crash resulting in denial of service attack. A flaw was found in the yajl library, which exists due to a memory leak within the yajl_tree_parse() function. This flaw allows a remote attacker to parse malicious JSON input to cause out-of-memory in the server, causing a crash, resulting in a denial of service attack.

Back to bug 2221249