Thanks all for the discussion.
@Tobias, thanks for marking the CVE in the list.
Best regards
Anton
Am Mi., 5. Juli 2023 um 17:56 Uhr schrieb Tobias Frost <
[email protected]>:
On Wed, Jul 05, 2023 at 09:06:15AM +0000, Bastien Roucaričs wrote:
Le mercredi 5 juillet 2023, 04:52:48 UTC Anton Gladky a écrit :
Hello,
I am looking into CVE-2023-33460 and I am not sure that ruby-yajl
is affected. There is no direct dependency on yajl, where the
vulnerability
was detected.
ruby-yajl include a old version of yajl 1.01.12
The vuln code was introduced by
https://github.com/lloyd/yajl/commit/cfa9f8fcb12d80dd5ebf94f5e6a607aab4d225fb in version 2.1.0 in 2010
This matches my investation, however, a small correction: This commit is already part of version 2.0.0.
I've added note in data/CVE/list accordingly.
--
Cheers,
tobi
<div dir="ltr"><div>Thanks all for the discussion.</div><div>@Tobias, thanks for marking the CVE in the list.</div><div><br></div><div>Best regards<br></div><div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><br>Anton</div><
/div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">Am Mi., 5. Juli 2023 um 17:56 Uhr schrieb Tobias Frost <<a href="mailto:
[email protected]">
[email protected]</a>>:<br></div><blockquote class="gmail_quote" style="
margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On Wed, Jul 05, 2023 at 09:06:15AM +0000, Bastien Roucaričs wrote:<br>
> Le mercredi 5 juillet 2023, 04:52:48 UTC Anton Gladky a écrit :<br>
> > Hello,<br>
> > <br>
> > I am looking into CVE-2023-33460 and I am not sure that ruby-yajl<br> > > is affected. There is no direct dependency on yajl, where the vulnerability<br>
> > was detected.<br>
> ruby-yajl include a old version of yajl 1.01.12<br>
> <br>
> The vuln code was introduced by <a href="
https://github.com/lloyd/yajl/commit/cfa9f8fcb12d80dd5ebf94f5e6a607aab4d225fb" rel="noreferrer" target="_blank">
https://github.com/lloyd/yajl/commit/cfa9f8fcb12d80dd5ebf94f5e6a607aab4d225fb</a> in version 2.1.
0 in 2010<br>
This matches my investation, however, a small correction: This commit is already part of version 2.0.0.<br>
I've added note in data/CVE/list accordingly.<br>
-- <br>
Cheers,<br>
tobi<br>
</blockquote></div>
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)