scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade yaml | Aug 30, 2017 | Dec 8, 2014 |
| Centos_linux | — | Upgrade libyaml-develUpgrade libyaml | Dec 1, 2016 | Dec 8, 2014 |
| Debian | — | Upgrade libyamlUpgrade pyyamlUpgrade libyaml-libyaml-perl | Jul 30, 2024 | Dec 8, 2014 |
| Oracle_linux | — | Upgrade libyaml-develUpgrade libyaml | Oct 16, 2024 | Dec 8, 2014 |
| Suse | — | Upgrade libyaml-develUpgrade python-pyyamlUpgrade libyaml-0-2Upgrade perl-YAML-LibYAML | Dec 18, 2015 | Dec 8, 2014 |
| Ubuntu | — | Upgrade libyaml-0-2Upgrade python3-yamlUpgrade libyaml-libyaml-perlUpgrade python-yaml | Nov 8, 2024 | Dec 8, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub