Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m75h-cghq-c8h5

Опубликовано: 31 авг. 2020
Источник: github
Github: Прошло ревью

Описание

Heap Based Buffer Overflow in libyaml

Versions 0.2.2 and earlier depend on native libyaml version 0.1.5 or earlier. As such, they are affected by a heap-based buffer overflow vulnerability that may result in a crash or arbitrary code execution when parsing YAML tags.

Recommendation

  • Update to version 0.2.3 that includes a version of LibYAML that contains a fix for this issue.

Пакеты

Наименование

libyaml

npm
Затронутые версииВерсия исправления

< 0.2.3

0.2.3

EPSS

Процентиль: 91%
0.0806
Низкий

Дефекты

CWE-119

Связанные уязвимости

ubuntu
почти 12 лет назад

The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.

redhat
почти 12 лет назад

The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.

nvd
почти 12 лет назад

The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.

debian
почти 12 лет назад

The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0 ...

fstec
почти 12 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 91%
0.0806
Низкий

Дефекты

CWE-119