The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Ruby | — | Apply OS X security update 2014-002 | Apr 5, 2017 | Feb 6, 2014 |
| Debian | — | Upgrade libyaml-libyaml-perlUpgrade libyaml | Jul 30, 2024 | Feb 6, 2014 |
| Freebsd | — | Upgrade libyamlUpgrade pkgUpgrade pkg-devel | Dec 10, 2025 | Feb 1, 2014 |
| Gentoo Linux | — | Upgrade dev-libs/libyaml. | Oct 30, 2017 | Feb 6, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 27, 2014 |
| Suse | — | Upgrade perl-YAML-LibYAMLUpgrade libyamlUpgrade libyaml-develUpgrade libyaml-0-2 | Feb 25, 2014 | Feb 6, 2014 |
| Ubuntu | — | Upgrade libyaml-libyaml-perlUpgrade libyaml-0-2 | Nov 8, 2024 | Feb 6, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub