MEDIUM
yaml-rust 0.4.0 and earlier is affected by: Uncontrolled Recursion
Published Jul 25, 2019
6.5
MEDIUMCVSS 3.0
EPSS 1.06%
Description
yaml-rust 0.4.0 and earlier is affected by: Uncontrolled Recursion. The impact is: Denial of service by impossible to catch abort. The component is: YamlLoader::load_from_str function. The attack vector is: Parsing of a malicious YAML document. The fixed version is: 0.4.1 and later.
Affected products
-
- Version 0.4.0 and earlier [fixed: 0.4.1 and later]StatusaffectedConstraints-
- Version
- ≤ 0.4.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-1927 Advisory
- https://github.com/chyh1990/yaml-rust/pull/109 x_refsource_MISCIssue TrackingPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-1927 | Advisory | |
| https://github.com/chyh1990/yaml-rust/pull/109 | x_refsource_MISCIssue TrackingPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dwf
Published Jul 25, 2019
Updated Aug 5, 2024
Reserved Mar 20, 2019
Link CVE-2019-1010182
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-1927 Assigner dwf
Published Jul 25, 2019
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2019-1927