CVE Database
/

CVE-2013-6393

Back to search

CVE-2013-6393

Published: Feb 6, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.

VendorProductVersions

n/a

n/a

affected
n/a

References

openSUSE-SU-2014:0273
vendor-advisory
x_refsource_SUSE
DSA-2870
vendor-advisory
x_refsource_DEBIAN
APPLE-SA-2014-10-16-3
vendor-advisory
x_refsource_APPLE
APPLE-SA-2014-04-22-1
vendor-advisory
x_refsource_APPLE
102716
vdb-entry
x_refsource_OSVDB
MDVSA-2015:060
vendor-advisory
x_refsource_MANDRIVA
65258
vdb-entry
x_refsource_BID
openSUSE-SU-2015:0319
vendor-advisory
x_refsource_SUSE
RHSA-2014:0355
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2014:0272
vendor-advisory
x_refsource_SUSE
RHSA-2014:0354
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2016:1067
vendor-advisory
x_refsource_SUSE
DSA-2850
vendor-advisory
x_refsource_DEBIAN
RHSA-2014:0353
vendor-advisory
x_refsource_REDHAT
USN-2098-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now