Improper resource allocation - Buffer overflow In libyaml
Description
Heap Based Buffer Overflow in libyaml Versions 0.2.2 and earlier depend on native libyaml version 0.1.5 or earlier. As such, they are affected by a heap-based buffer overflow vulnerability that may result in a crash or arbitrary code execution when parsing YAML tags.
Recommendation
Update to version 0.2.3 that includes a version of LibYAML that contains a fix for this issue.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 0.2.3 | ||
debian 13 | 0.1.4-3 | ||
debian 14 | 0.1.4-3 | ||
debian 12 | 0.41-4 | ||
debian 12 | 0.1.4-3 | ||
debian 11 | 0.41-4 | ||
debian 14 | 0.41-4 | ||
debian 11 | 0.1.4-3 | ||
debian 13 | 0.41-4 | ||
rpm rhel6 | - | - |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20. 21. 22. 23.