[Forgot Password]
Login  Register Subscribe

24128

 
 

131573

 
 

110139

 
 

909

 
 

85964

 
 

136

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2014-9130Date: (C)2014-12-09   (M)2018-05-10


scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : CVSS Score : 5.0
Exploit Score: Exploit Score: 10.0
Impact Score: Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: Access Vector: NETWORK
Attack Complexity: Access Complexity: LOW
Privileges Required: Authentication: NONE
User Interaction: Confidentiality: NONE
Scope: Integrity: NONE
Confidentiality: Availability: PARTIAL
Integrity:  
Availability:  
  
Reference:
SECUNIA-59947
SECUNIA-60944
SECUNIA-62164
SECUNIA-62174
SECUNIA-62176
SECUNIA-62705
SECUNIA-62723
SECUNIA-62774
BID-71349
DSA-3102
DSA-3103
DSA-3115
MDVSA-2014:242
MDVSA-2015:060
RHSA-2015:0100
RHSA-2015:0112
RHSA-2015:0260
USN-2461-1
USN-2461-2
USN-2461-3
http://www.openwall.com/lists/oss-security/2014/11/28/8
http://www.openwall.com/lists/oss-security/2014/11/28/1
http://www.openwall.com/lists/oss-security/2014/11/29/3
http://advisories.mageia.org/MGASA-2014-0508.html
http://linux.oracle.com/errata/ELSA-2015-0100.html
https://bitbucket.org/xi/libyaml/commits/2b9156756423e967cfd09a61d125d883fca6f4f2
https://bitbucket.org/xi/libyaml/issue/10/wrapped-strings-cause-assert-failure
https://puppet.com/security/cve/cve-2014-9130
libyaml-cve20149130-dos(99047)
openSUSE-SU-2015:0319
openSUSE-SU-2016:1067

CPE    2
cpe:/a:pyyaml:libyaml:0.1.5
cpe:/a:pyyaml:libyaml:0.1.6
CWE    1
CWE-20
OVAL    21
oval:org.secpod.oval:def:601866
oval:org.secpod.oval:def:702361
oval:org.secpod.oval:def:702370
oval:org.secpod.oval:def:702376
...

© SecPod Technologies