libyaml: heap-based buffer overflow when parsing YAML tags
Published Feb 6, 2014
6.8
MEDIUMCVSS 2.0
EPSS 7.39%
Description
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.
Affected products
No data.
Configuration 1
Configuration 2
- 12.04
- 12.10
- 13.10
Configuration 4
- 6.0
- 7.0
No data.
OpenStack 3 for RHEL 6
libyaml-0:0.1.3-1.4.el6
Fixed · RHSA-2014:0353
OpenStack 3 for RHEL 6
ruby193-libyaml-0:0.1.4-5.1.el6
Fixed · RHSA-2014:0364
OpenStack 4 for RHEL 6
libyaml-0:0.1.3-1.4.el6
Fixed · RHSA-2014:0354
Red Hat Common for RHEL 6
libyaml-0:0.1.3-1.4.el6
Fixed · RHSA-2014:0415
Red Hat Software Collections for RHEL-6
ruby193-libyaml-0:0.1.4-5.1.el6
Fixed · RHSA-2014:0355
CloudForms Management Engine 5
ruby193-libyaml
Not affected
OpenShift Enterprise 1
ruby193-libyaml
Will not fix
Red Hat Enterprise Linux 6
libyaml
Affected
Red Hat Enterprise Linux 7
libyaml
Not affected
Red Hat Enterprise MRG 1
libyaml
Will not fix
Red Hat Enterprise MRG 2
libyaml
Will not fix
Red Hat Satellite 5
libyaml
Will not fix
Red Hat Satellite 6
libyaml
Not affected
Red Hat Satellite 6
ruby193-libyaml
Not affected
Red Hat Software Collections
libyaml
Affected
Red Hat Subscription Asset Manager
libyaml
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 3 for RHEL 6 | libyaml-0:0.1.3-1.4.el6 | Fixed | RHSA-2014:0353 |
| OpenStack 3 for RHEL 6 | ruby193-libyaml-0:0.1.4-5.1.el6 | Fixed | RHSA-2014:0364 |
| OpenStack 4 for RHEL 6 | libyaml-0:0.1.3-1.4.el6 | Fixed | RHSA-2014:0354 |
| Red Hat Common for RHEL 6 | libyaml-0:0.1.3-1.4.el6 | Fixed | RHSA-2014:0415 |
| Red Hat Software Collections for RHEL-6 | ruby193-libyaml-0:0.1.4-5.1.el6 | Fixed | RHSA-2014:0355 |
| CloudForms Management Engine 5 | ruby193-libyaml | Not affected | n/a |
| OpenShift Enterprise 1 | ruby193-libyaml | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | libyaml | Affected | n/a |
| Red Hat Enterprise Linux 7 | libyaml | Not affected | n/a |
| Red Hat Enterprise MRG 1 | libyaml | Will not fix | n/a |
| Red Hat Enterprise MRG 2 | libyaml | Will not fix | n/a |
| Red Hat Satellite 5 | libyaml | Will not fix | n/a |
| Red Hat Satellite 6 | libyaml | Not affected | n/a |
| Red Hat Satellite 6 | ruby193-libyaml | Not affected | n/a |
| Red Hat Software Collections | libyaml | Affected | n/a |
| Red Hat Subscription Asset Manager | libyaml | Will not fix | n/a |
libyaml
npm
Introduced 0 Fixed 0.2.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | libyaml | 0 | 0.2.3 |
Remediation
Red Hat statement
The Red Hat security response team has rated this issue as having low security impact in Red Hat Enterpise MRG 1 and 2, CloudForms 3, and Red Hat Network Satellite 5. This issue is not currently planned to be addressed in future updates.Redhat satellite 6 does not ship libyaml The Red Hat security response team has rated this issue as having low security impact in Red Hat Update Infrastructure. A future update may address this issue. The Red Hat security response team has rated this issue as having moderate security impact in Subscription Asset Manager 1. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 7.39% (0.07386) | 94.25th | v5 (v2026.06.15) |
| Jul 23, 2026 | 8.05% (0.08053) | 94.19th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.23% (0.09234) | 94.68th | v5 (v2026.06.15) |
| Sep 29, 2025 | 8.06% (0.08060) | 91.81th | v4 (v2025.03.14) |
| Sep 22, 2025 | 6.32% (0.06320) | 90.60th | v4 (v2025.03.14) |
| May 11, 2025 | 9.01% (0.09006) | 92.14th | v4 (v2025.03.14) |
| May 6, 2025 | 7.20% (0.07201) | 91.09th | v4 (v2025.03.14) |
| Mar 30, 2025 | 8.34% (0.08342) | 91.46th | v4 (v2025.03.14) |
| Mar 29, 2025 | 9.35% (0.09350) | 87.82th | v4 (v2025.03.14) |
| Mar 17, 2025 | 8.34% (0.08342) | 91.66th | v4 (v2025.03.14) |
| Dec 12, 2024 | 2.57% (0.02575) | 90.63th | v3 (v2023.03.01) |
| Jul 1, 2024 | 2.48% (0.02476) | 90.16th | v3 (v2023.03.01) |
| Dec 20, 2023 | 3.08% (0.03085) | 90.00th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.20% (0.02199) | 87.65th | v3 (v2023.03.01) |
| Mar 6, 2023 | 6.60% (0.06604) | 91.53th | v2 (v2022.01.01) |
| Apr 1, 2022 | 6.60% (0.06604) | 90.72th | v2 (v2022.01.01) |
| Feb 4, 2022 | 6.60% (0.06604) | 78.62th | v2 (v2022.01.01) |
References (30)
- http://advisories.mageia.org/MGASA-2014-0040.html x_refsource_CONFIRMThird Party Advisory
- http://archives.neohapsis.com/archives/bugtraq/2014-04/0134.html vendor-advisoryx_refsource_APPLEBroken Link
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0103.html vendor-advisoryx_refsource_APPLEBroken Link
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=2013-6393
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00064.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00065.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00078.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-04/msg00050.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://osvdb.org/102716 vdb-entryx_refsource_OSVDB
- http://rhn.redhat.com/errata/RHSA-2014-0353.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0354.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0355.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.debian.org/security/2014/dsa-2850 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.debian.org/security/2014/dsa-2870 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:060 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.securityfocus.com/bid/65258 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2098-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2013-6393 Vendor Advisory
- https://bitbucket.org/xi/libyaml/commits/bce8b60f0b9af69fa9fab3093d0a41ba243de048
- https://bitbucket.org/xi/libyaml/commits/tag/0.1.5 x_refsource_CONFIRMIssue Tracking
- https://bugzilla.redhat.com/attachment.cgi?id=847926&action=diff x_refsource_MISCIssue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=1033990 x_refsource_CONFIRMIssue TrackingPatch
- https://github.com/advisories/GHSA-m75h-cghq-c8h5 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-6393
- https://puppet.com/security/cve/cve-2013-6393 x_refsource_CONFIRM
- https://support.apple.com/kb/HT6536 x_refsource_CONFIRMThird Party Advisory
- https://web.archive.org/web/20140302205713/http://www.securityfocus.com/bid/65258
- https://web.archive.org/web/20150523055002/http://www.mandriva.com/en/support/security/advisories/advisory/MDVSA-2015:060/?name=MDVSA-2015:060
- https://www.cve.org/CVERecord?id=CVE-2013-6393
- https://www.npmjs.com/advisories/21
Change history (0)
No recorded changes yet.