Back

MEDIUM

libyaml: heap-based buffer overflow when parsing URLs

Published Mar 28, 2014

Description

Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execute arbitrary code via a long sequence of percent-encoded characters in a URI in a YAML file.

Affected products

Remediation

Red Hat statement

Redhat satellite does not ship libyaml package but instead consumes the package from the RHEL distribution which is why it has been marked as not affected.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

References (26)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 28, 2014
Updated Aug 6, 2024
Reserved Mar 17, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 27, 2014