ELA-888-1 yajl security update

memory leak

2023-07-01
Packageyajl
Version2.1.0-2+deb8u1 (jessie), 2.1.0-2+deb9u1 (stretch)
Related CVEs CVE-2023-33460


A memory leak has been found in yajl, a JSON parser / small validating JSON generator written in ANSI C, which might allow an attacker to cause an out of memory situation and potentially causing a crash.



For Debian 8 jessie, these problems have been fixed in version 2.1.0-2+deb8u1.

For Debian 9 stretch, these problems have been fixed in version 2.1.0-2+deb9u1.

We recommend that you upgrade your yajl packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.