[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

96078

 
 

909

 
 

78009

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2014-9130

Date: (C)2014-12-09   (M)2017-09-11
 
CVSS Score: 5.0Access Vector: NETWORK
Exploitability Subscore: 10.0Access Complexity: LOW
Impact Subscore: 2.9Authentication: NONE
 Confidentiality: NONE
 Integrity: NONE
 Availability: PARTIAL











scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping.

Reference:
SECUNIA-59947
SECUNIA-60944
SECUNIA-62164
SECUNIA-62174
SECUNIA-62176
SECUNIA-62705
SECUNIA-62723
SECUNIA-62774
BID-71349
DSA-3102
DSA-3103
DSA-3115
MDVSA-2014:242
MDVSA-2015:060
RHSA-2015:0100
RHSA-2015:0112
RHSA-2015:0260
USN-2461-1
USN-2461-2
USN-2461-3
http://www.openwall.com/lists/oss-security/2014/11/28/8
http://www.openwall.com/lists/oss-security/2014/11/28/1
http://www.openwall.com/lists/oss-security/2014/11/29/3
http://advisories.mageia.org/MGASA-2014-0508.html
http://linux.oracle.com/errata/ELSA-2015-0100.html
https://bitbucket.org/xi/libyaml/commits/2b9156756423e967cfd09a61d125d883fca6f4f2
https://bitbucket.org/xi/libyaml/issue/10/wrapped-strings-cause-assert-failure
libyaml-cve20149130-dos(99047)
openSUSE-SU-2015:0319
openSUSE-SU-2016:1067

CPE    2
cpe:/a:pyyaml:libyaml:0.1.5
cpe:/a:pyyaml:libyaml:0.1.6
CWE    1
CWE-20
OVAL    21
oval:org.secpod.oval:def:108631
oval:org.secpod.oval:def:1500901
oval:org.secpod.oval:def:601866
oval:org.secpod.oval:def:702361
...

© 2013 SecPod Technologies