CPANSA-YAML-LibYAML-2014-9130: YAML-LibYAML vulnerability
Publisher | giterlizzi | Document category | csaf_security_advisory |
---|---|---|---|
Initial release date | 2014-12-08T00:00:00 | Engine | CSAF Perl Toolkit 0.25 |
Current release date | 2014-12-08T00:00:00 | Build Date | |
Current version | 1 | Status | final |
CVSS v3.1 Base Score | Severity | ||
Original language | Language | en | |
Also referred to |
Vulnerability Description
scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping.
Vulnerabilities
CVE-2014-9130
Vulnerability Descriptionscanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping.
Weakness | CWE-20 : Improper Input Validation |
---|
Product status
Known affected
Product | Score | ||||||||
---|---|---|---|---|---|---|---|---|---|
YAML-LibYAML less than 0.53 |
|
Fixed
- YAML-LibYAML greater than or equal 0.54
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-YAML-LibYAML-2014-9130 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2014/cpansa-yaml-libyaml-2014-9130.json - http://www.openwall.com/lists/oss-security/2014/11/29/3 external
http://www.openwall.com/lists/oss-security/2014/11/29/3 - http://www.openwall.com/lists/oss-security/2014/11/28/8 external
http://www.openwall.com/lists/oss-security/2014/11/28/8 - https://bitbucket.org/xi/libyaml/commits/2b9156756423e967cfd09a61d125d883fca6f4f2 external
https://bitbucket.org/xi/libyaml/commits/2b9156756423e967cfd09a61d125d883fca6f4f2 - http://www.securityfocus.com/bid/71349 external
http://www.securityfocus.com/bid/71349 - http://secunia.com/advisories/59947 external
http://secunia.com/advisories/59947 - https://bitbucket.org/xi/libyaml/issue/10/wrapped-strings-cause-assert-failure external
https://bitbucket.org/xi/libyaml/issue/10/wrapped-strings-cause-assert-failure - http://secunia.com/advisories/60944 external
http://secunia.com/advisories/60944 - http://www.openwall.com/lists/oss-security/2014/11/28/1 external
http://www.openwall.com/lists/oss-security/2014/11/28/1 - http://linux.oracle.com/errata/ELSA-2015-0100.html external
http://linux.oracle.com/errata/ELSA-2015-0100.html - http://secunia.com/advisories/62723 external
http://secunia.com/advisories/62723 - http://secunia.com/advisories/62705 external
http://secunia.com/advisories/62705 - http://secunia.com/advisories/62774 external
http://secunia.com/advisories/62774 - http://www.ubuntu.com/usn/USN-2461-2 external
http://www.ubuntu.com/usn/USN-2461-2 - http://www.ubuntu.com/usn/USN-2461-3 external
http://www.ubuntu.com/usn/USN-2461-3 - http://www.ubuntu.com/usn/USN-2461-1 external
http://www.ubuntu.com/usn/USN-2461-1 - http://rhn.redhat.com/errata/RHSA-2015-0100.html external
http://rhn.redhat.com/errata/RHSA-2015-0100.html - http://www.debian.org/security/2014/dsa-3103 external
http://www.debian.org/security/2014/dsa-3103 - http://rhn.redhat.com/errata/RHSA-2015-0112.html external
http://rhn.redhat.com/errata/RHSA-2015-0112.html - http://www.debian.org/security/2014/dsa-3102 external
http://www.debian.org/security/2014/dsa-3102 - http://www.debian.org/security/2014/dsa-3115 external
http://www.debian.org/security/2014/dsa-3115 - http://rhn.redhat.com/errata/RHSA-2015-0260.html external
http://rhn.redhat.com/errata/RHSA-2015-0260.html - http://lists.opensuse.org/opensuse-updates/2015-02/msg00078.html external
http://lists.opensuse.org/opensuse-updates/2015-02/msg00078.html - http://www.mandriva.com/security/advisories?name=MDVSA-2015:060 external
http://www.mandriva.com/security/advisories?name=MDVSA-2015:060 - http://www.mandriva.com/security/advisories?name=MDVSA-2014:242 external
http://www.mandriva.com/security/advisories?name=MDVSA-2014:242 - http://advisories.mageia.org/MGASA-2014-0508.html external
http://advisories.mageia.org/MGASA-2014-0508.html - http://lists.opensuse.org/opensuse-updates/2016-04/msg00050.html external
http://lists.opensuse.org/opensuse-updates/2016-04/msg00050.html - http://secunia.com/advisories/62176 external
http://secunia.com/advisories/62176 - http://secunia.com/advisories/62174 external
http://secunia.com/advisories/62174 - http://secunia.com/advisories/62164 external
http://secunia.com/advisories/62164 - https://exchange.xforce.ibmcloud.com/vulnerabilities/99047 external
https://exchange.xforce.ibmcloud.com/vulnerabilities/99047 - https://puppet.com/security/cve/cve-2014-9130 external
https://puppet.com/security/cve/cve-2014-9130 - CVE-2014-9130 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2014-9130
Revision history
Version | Date of the revision | Summary of the revision |
---|---|---|
1 | Mon Dec 8 00:00:00 2014 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/