Skip to content

CVE-2014-9130 @ Python-PyYAML-3.12 #30

@cx-pedro-lopes

Description

@cx-pedro-lopes

Vulnerable Package issue exists @ Python-PyYAML-3.12 in branch main

scanner.c in LibYAML through 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping.

Namespace: pedrompflopes
Repository: small-project
Repository Url: https://github.com/pedrompflopes/small-project
CxAST-Project: pedrompflopes/small-project
CxAST platform scan: c8ffe959-aafe-486d-a7e7-1ba92f6aee49
Branch: main
Application: small-project
Severity: MEDIUM
State: TO_VERIFY
Status: RECURRENT
CWE: CWE-20


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: NONE
Availability impact: PARTIAL
Remediation Upgrade Recommendation: 5.4


References
Commit
Advisory
Issue
Mail Thread

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions