Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-35325

Опубликовано: 13 июн. 2024
Источник: redhat
CVSS3: 6.5

Описание

A vulnerability was found in libyaml in versions up to 0.2.5. This issue affects the yaml_event_delete function in the /src/libyaml/src/api.c. file, leading to a double-free problem.

Отчет

To create the conditions for this vulnerability, yaml_event_delete must be called after yaml_emitter_delete, creating double free whenever there are anchors or tags involved. This ordering implies improper API usage, as such, Red Hat does not consider this a vulnerability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libyamlNot affected
Red Hat Enterprise Linux 10python-ruamel-yaml-clibNot affected
Red Hat Enterprise Linux 6libyamlNot affected
Red Hat Enterprise Linux 7libyamlNot affected
Red Hat Enterprise Linux 8libyamlNot affected
Red Hat Enterprise Linux 8perl-YAML-LibYAMLNot affected
Red Hat Enterprise Linux 9libyamlNot affected
Red Hat Enterprise Linux 9python-ruamel-yaml-clibNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-415
https://bugzilla.redhat.com/show_bug.cgi?id=2292350libyaml: double-free in yaml_event_delete in /src/libyaml/src/api.c

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
около 2 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

nvd
около 2 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

CVSS3: 9.8
github
около 2 лет назад

A vulnerability was found in libyaml up to 0.2.5. Affected by this issue is the function yaml_event_delete of the file /src/libyaml/src/api.c. The manipulation leads to a double-free.

6.5 Medium

CVSS3