CVE Database
/

CVE-2012-1152

Back to search

CVE-2012-1152

Published: Sep 9, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple format string vulnerabilities in the error reporting functionality in the YAML::LibYAML (aka YAML-LibYAML and perl-YAML-LibYAML) module 0.38 for Perl allow remote attackers to cause a denial of service (process crash) via format string specifiers in a (1) YAML stream to the Load function, (2) YAML node to the load_node function, (3) YAML mapping to the load_mapping function, or (4) YAML sequence to the load_sequence function.

VendorProductVersions

n/a

n/a

affected
n/a

References

openSUSE-SU-2012:1000
vendor-advisory
x_refsource_SUSE
FEDORA-2012-4997
vendor-advisory
x_refsource_FEDORA
48317
third-party-advisory
x_refsource_SECUNIA
FEDORA-2012-5035
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2015:0319
vendor-advisory
x_refsource_SUSE
52381
vdb-entry
x_refsource_BID
yaml-load-format-string(73856)
vdb-entry
x_refsource_XF
50277
third-party-advisory
x_refsource_SECUNIA
FEDORA-2012-4871
vendor-advisory
x_refsource_FEDORA
DSA-2432
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now