libyaml: assert failure when processing wrapped strings
Published Dec 8, 2014
5.0
MEDIUMCVSS 2.0
EPSS 13.20%
Description
scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping.
Affected products
No data.
No data.
OpenStack 4 for RHEL 6
libyaml-0:0.1.3-4.el6_6
Fixed · RHSA-2015:0260
Red Hat Enterprise Linux 6
libyaml-0:0.1.3-4.el6_6
Fixed · RHSA-2015:0100
Red Hat Enterprise Linux 7
libyaml-0:0.1.4-11.el7_0
Fixed · RHSA-2015:0100
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
libyaml-0:0.1.3-4.el6_6
Fixed · RHSA-2015:0260
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6
libyaml-0:0.1.3-4.el6_6
Fixed · RHSA-2015:0112
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS
libyaml-0:0.1.3-4.el6_6
Fixed · RHSA-2015:0112
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUS
libyaml-0:0.1.3-4.el6_6
Fixed · RHSA-2015:0112
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUS
libyaml-0:0.1.3-4.el6_6
Fixed · RHSA-2015:0112
CloudForms Management Engine 5
mingw-libyaml
Not affected
Red Hat Enterprise MRG 1
libyaml
Will not fix
Red Hat Enterprise MRG 2
libyaml
Will not fix
Red Hat Satellite 5
libyaml
Fix deferred
Red Hat Satellite 6
libyaml
Fix deferred
Red Hat Satellite 6
ruby193-libyaml
Fix deferred
Red Hat Subscription Asset Manager
libyaml
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 4 for RHEL 6 | libyaml-0:0.1.3-4.el6_6 | Fixed | RHSA-2015:0260 |
| Red Hat Enterprise Linux 6 | libyaml-0:0.1.3-4.el6_6 | Fixed | RHSA-2015:0100 |
| Red Hat Enterprise Linux 7 | libyaml-0:0.1.4-11.el7_0 | Fixed | RHSA-2015:0100 |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | libyaml-0:0.1.3-4.el6_6 | Fixed | RHSA-2015:0260 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 | libyaml-0:0.1.3-4.el6_6 | Fixed | RHSA-2015:0112 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS | libyaml-0:0.1.3-4.el6_6 | Fixed | RHSA-2015:0112 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUS | libyaml-0:0.1.3-4.el6_6 | Fixed | RHSA-2015:0112 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUS | libyaml-0:0.1.3-4.el6_6 | Fixed | RHSA-2015:0112 |
| CloudForms Management Engine 5 | mingw-libyaml | Not affected | n/a |
| Red Hat Enterprise MRG 1 | libyaml | Will not fix | n/a |
| Red Hat Enterprise MRG 2 | libyaml | Will not fix | n/a |
| Red Hat Satellite 5 | libyaml | Fix deferred | n/a |
| Red Hat Satellite 6 | libyaml | Fix deferred | n/a |
| Red Hat Satellite 6 | ruby193-libyaml | Fix deferred | n/a |
| Red Hat Subscription Asset Manager | libyaml | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (51 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 13.20% (0.13195) | 96.26th | v5 (v2026.06.15) |
| Jun 15, 2026 | 13.20% (0.13195) | 95.86th | v5 (v2026.06.15) |
| May 27, 2026 | 57.63% (0.57630) | 98.19th | v4 (v2025.03.14) |
| Mar 16, 2026 | 55.34% (0.55338) | 98.03th | v4 (v2025.03.14) |
| Mar 4, 2026 | 60.10% (0.60101) | 98.23th | v4 (v2025.03.14) |
| Mar 1, 2026 | 46.72% (0.46721) | 97.62th | v4 (v2025.03.14) |
| Feb 26, 2026 | 60.10% (0.60101) | 98.23th | v4 (v2025.03.14) |
| Feb 4, 2026 | 57.63% (0.57630) | 98.09th | v4 (v2025.03.14) |
| Feb 1, 2026 | 44.36% (0.44360) | 97.47th | v4 (v2025.03.14) |
| Jan 4, 2026 | 57.63% (0.57630) | 98.07th | v4 (v2025.03.14) |
| Jan 1, 2026 | 44.36% (0.44360) | 97.45th | v4 (v2025.03.14) |
| Dec 4, 2025 | 57.63% (0.57630) | 98.04th | v4 (v2025.03.14) |
| Dec 1, 2025 | 44.36% (0.44360) | 97.42th | v4 (v2025.03.14) |
| Nov 4, 2025 | 60.75% (0.60753) | 98.20th | v4 (v2025.03.14) |
| Nov 1, 2025 | 43.05% (0.43050) | 97.36th | v4 (v2025.03.14) |
| Oct 4, 2025 | 60.75% (0.60753) | 98.23th | v4 (v2025.03.14) |
| Oct 1, 2025 | 43.05% (0.43050) | 97.41th | v4 (v2025.03.14) |
| Sep 4, 2025 | 60.75% (0.60753) | 98.25th | v4 (v2025.03.14) |
| Sep 1, 2025 | 43.05% (0.43050) | 97.42th | v4 (v2025.03.14) |
| Aug 4, 2025 | 60.75% (0.60753) | 98.21th | v4 (v2025.03.14) |
| Aug 1, 2025 | 43.05% (0.43050) | 97.40th | v4 (v2025.03.14) |
| Jul 6, 2025 | 60.75% (0.60753) | 98.18th | v4 (v2025.03.14) |
| Jul 1, 2025 | 43.05% (0.43050) | 97.35th | v4 (v2025.03.14) |
| Jun 4, 2025 | 60.75% (0.60753) | 98.16th | v4 (v2025.03.14) |
| Jun 1, 2025 | 42.68% (0.42678) | 97.31th | v4 (v2025.03.14) |
| May 4, 2025 | 60.42% (0.60423) | 98.14th | v4 (v2025.03.14) |
| May 1, 2025 | 42.68% (0.42678) | 97.29th | v4 (v2025.03.14) |
| Apr 13, 2025 | 60.42% (0.60423) | 98.13th | v4 (v2025.03.14) |
| Apr 12, 2025 | 42.68% (0.42678) | 97.22th | v4 (v2025.03.14) |
| Apr 5, 2025 | 60.75% (0.60753) | 98.14th | v4 (v2025.03.14) |
| Apr 4, 2025 | 43.05% (0.43050) | 97.23th | v4 (v2025.03.14) |
| Apr 1, 2025 | 60.75% (0.60753) | 98.13th | v4 (v2025.03.14) |
| Mar 31, 2025 | 43.05% (0.43050) | 97.22th | v4 (v2025.03.14) |
| Mar 30, 2025 | 60.75% (0.60753) | 98.13th | v4 (v2025.03.14) |
| Mar 29, 2025 | 70.41% (0.70407) | 98.22th | v4 (v2025.03.14) |
| Mar 28, 2025 | 60.75% (0.60753) | 98.13th | v4 (v2025.03.14) |
| Mar 27, 2025 | 43.05% (0.43050) | 97.04th | v4 (v2025.03.14) |
| Mar 25, 2025 | 60.75% (0.60753) | 98.15th | v4 (v2025.03.14) |
| Mar 24, 2025 | 43.05% (0.43050) | 97.20th | v4 (v2025.03.14) |
| Mar 20, 2025 | 60.75% (0.60753) | 98.16th | v4 (v2025.03.14) |
| Mar 19, 2025 | 58.30% (0.58304) | 97.94th | v4 (v2025.03.14) |
| Mar 18, 2025 | 40.70% (0.40698) | 97.08th | v4 (v2025.03.14) |
| Mar 17, 2025 | 58.30% (0.58304) | 97.97th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.78% (0.01776) | 88.53th | v3 (v2023.03.01) |
| Jul 20, 2024 | 1.78% (0.01776) | 88.22th | v3 (v2023.03.01) |
| Jun 3, 2024 | 1.70% (0.01696) | 87.75th | v3 (v2023.03.01) |
| Jan 2, 2024 | 1.84% (0.01842) | 86.98th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.65% (0.01650) | 85.59th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.69% (0.02686) | 62.66th | v2 (v2022.01.01) |
References (35)
- http://advisories.mageia.org/MGASA-2014-0508.html x_refsource_CONFIRM
- http://linux.oracle.com/errata/ELSA-2015-0100.html x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00078.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2016-04/msg00050.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2015-0100.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0112.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0260.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/59947 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60944 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62164 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62174 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62176 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62705 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62723 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/62774 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2014/dsa-3102 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2014/dsa-3103 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2014/dsa-3115 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:242 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:060 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2014/11/28/1 mailing-listx_refsource_MLISTExploit
- http://www.openwall.com/lists/oss-security/2014/11/28/8 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2014/11/29/3 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/71349 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-2461-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2461-2 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2461-3 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2014-9130 Vendor Advisory
- https://bitbucket.org/xi/libyaml/commits/2b9156756423e967cfd09a61d125d883fca6f4f2 x_refsource_CONFIRMExploit
- https://bitbucket.org/xi/libyaml/issue/10/wrapped-strings-cause-assert-failure x_refsource_MISCExploit
- https://bugzilla.redhat.com/show_bug.cgi?id=1169369 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99047 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2014-9130
- https://puppet.com/security/cve/cve-2014-9130 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2014-9130
Change history (0)
No recorded changes yet.