Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-2525

Опубликовано: 27 мар. 2014
Источник: redhat
CVSS2: 6.8

Описание

Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execute arbitrary code via a long sequence of percent-encoded characters in a URI in a YAML file.

A heap based buffer overflow exists in the libyaml package such that an attacker by supplying a specially crafted yaml document when parsed by the application might result in remote code execution leading to complete compromise of the system.

Отчет

Redhat satellite does not ship libyaml package but instead consumes the package from the RHEL distribution which is why it has been marked as not affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5ruby193-libyamlNot affected
OpenShift Enterprise 1ruby193-libyamlWill not fix
Red Hat Enterprise Linux 6libyamlAffected
Red Hat Enterprise Linux 7libyamlNot affected
Red Hat Enterprise MRG 1libyamlWill not fix
Red Hat Enterprise MRG 2libyamlWill not fix
Red Hat Satellite 5libyamlNot affected
Red Hat Satellite 6libyamlNot affected
Red Hat Software CollectionslibyamlNot affected
Red Hat Subscription Asset ManagerlibyamlAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1078083libyaml: heap-based buffer overflow when parsing URLs

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execute arbitrary code via a long sequence of percent-encoded characters in a URI in a YAML file.

nvd
больше 12 лет назад

Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execute arbitrary code via a long sequence of percent-encoded characters in a URI in a YAML file.

debian
больше 12 лет назад

Heap-based buffer overflow in the yaml_parser_scan_uri_escapes functio ...

github
около 4 лет назад

Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execute arbitrary code via a long sequence of percent-encoded characters in a URI in a YAML file.

fstec
около 12 лет назад

Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

6.8 Medium

CVSS2