Описание
A vulnerability was found in libyaml in versions up to 0.2.5. This issue affects the yaml_event_delete function in the /src/libyaml/src/api.c. file, leading to a double-free problem.
Отчет
To create the conditions for this vulnerability, yaml_event_delete must be called after yaml_emitter_delete, creating double free whenever there are anchors or tags involved. This ordering implies improper API usage, as such, Red Hat does not consider this a vulnerability.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libyaml | Not affected | ||
| Red Hat Enterprise Linux 10 | python-ruamel-yaml-clib | Not affected | ||
| Red Hat Enterprise Linux 6 | libyaml | Not affected | ||
| Red Hat Enterprise Linux 7 | libyaml | Not affected | ||
| Red Hat Enterprise Linux 8 | libyaml | Not affected | ||
| Red Hat Enterprise Linux 8 | perl-YAML-LibYAML | Not affected | ||
| Red Hat Enterprise Linux 9 | libyaml | Not affected | ||
| Red Hat Enterprise Linux 9 | python-ruamel-yaml-clib | Not affected |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
A vulnerability was found in libyaml up to 0.2.5. Affected by this issue is the function yaml_event_delete of the file /src/libyaml/src/api.c. The manipulation leads to a double-free.
6.5 Medium
CVSS3