Asymmetric denial of service In libyaml-libyaml-perl
Description
Multiple format string vulnerabilities in the error reporting functionality in the YAML::LibYAML (aka YAML-LibYAML and perl-YAML-LibYAML) module 0.38 for Perl allow remote attackers to cause a denial of service (process crash) via format string specifiers in a (1) YAML stream to the Load function, (2) YAML node to the load_node function, (3) YAML mapping to the load_mapping function, or (4) YAML sequence to the load_sequence function.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 0.38-2 | ||
debian 12 | 0.38-2 | ||
debian 14 | 0.38-2 | ||
debian 11 | 0.38-2 |
Aliases
1. 2. 3. 4. 5.