发布时间: 2024年5月10日
修改时间: 2024年10月18日
A vulnerability was found in yaml libyaml up to 0.2.5 and classified as critical. Affected by this issue is the function yaml_emitter_emit_flow_sequence_item of the file /src/libyaml/src/emitter.c. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259052. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
NVD | openEuler | |
---|---|---|
Confidentiality | Low | Low |
Attack Vector | Network | Network |
CVSS评分 | 7.3 | |
Attack Complexity | Low | Low |
Privileges Required | None | None |
Scope | Unchanged | Unchanged |
Integrity | Low | Low |
User Interaction | None | None |
Availability | Low | Low |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2024-3499 | libyaml security update | 2024年5月10日 |
KylinSec-SA-2024-4068 | libyaml security update | 2024年10月18日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | libyaml | Fixed |
KY3.4-5A | libyaml | Fixed |
KY3.5.1 | libyaml | Unaffected |
KY3.5.2 | libyaml | Fixed |