CVE-2022-24795 is an integer overflow vulnerability affecting yajl-ruby, a C binding for the YAJL JSON parsing library, specifically in its 1.x and 2.x branches. This flaw can lead to heap memory corruption when processing large inputs (around 2GB), primarily impacting process availability. Rated 7.5 HIGH on CVSS, it can be exploited remotely with low attack complexity, though arbitrary code execution is deemed unlikely. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.2CPE matchmatch criteria | cpe:2.3:a:yajl-ruby_project:yajl-ruby:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-24795
Sep 10, 2024Buffer Overflow and Integer Overflow in yajl-ruby
Apr 12, 2022Buffer Overflow in yajl-ruby
Apr 5, 2022yajl: heap-based buffer overflow when handling large inputs due to an integer overflow
Apr 5, 2022