Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW03NWgtY2docS1jOGg1

Heap Based Buffer Overflow in libyaml

Versions 0.2.2 and earlier depend on native libyaml version 0.1.5 or earlier. As such, they are affected by a heap-based buffer overflow vulnerability that may result in a crash or arbitrary code execution when parsing YAML tags.

Recommendation

Permalink: https://github.com/advisories/GHSA-m75h-cghq-c8h5
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW03NWgtY2docS1jOGg1
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: over 3 years ago
Updated: 8 months ago


Identifiers: GHSA-m75h-cghq-c8h5, CVE-2013-6393
References: Repository: https://bitbucket.org/xi/libyaml
Blast Radius: 0.0

Affected Packages

npm:libyaml
Dependent packages: 18
Dependent repositories: 22
Downloads: 362 last month
Affected Version Ranges: < 0.2.3
Fixed in: 0.2.3
All affected versions: 0.0.1, 0.0.2, 0.0.3, 0.0.4, 0.1.0, 0.1.1, 0.2.0, 0.2.1, 0.2.2
All unaffected versions: 0.2.3, 0.2.4, 0.2.5