5.5
CVSSv3

CVE-2017-5950

Published: 03/04/2017 Updated: 11/04/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The SingleDocParser::HandleNode function in yaml-cpp (aka LibYaml-C++) 0.5.3 allows remote malicious users to cause a denial of service (stack consumption and application crash) via a crafted YAML file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

yaml-cpp project yaml-cpp 0.5.3

Vendor Advisories

Debian Bug report logs - #918145 yaml-cpp: CVE-2018-20574: Stack Overflow in SingleDocParser::HandleFlowMap() Package: src:yaml-cpp; Maintainer for src:yaml-cpp is Simon Quigley <tsimonq2@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 3 Jan 2019 20:09:01 UTC Severity: important Tags: s ...
Debian Bug report logs - #859891 yaml-cpp: CVE-2017-5950 Package: src:yaml-cpp; Maintainer for src:yaml-cpp is Simon Quigley <tsimonq2@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 8 Apr 2017 20:00:01 UTC Severity: important Tags: security, upstream Found in versions yaml-cpp/062-2 ...
The SingleDocParser::HandleNode function in yaml-cpp (aka LibYaml-C++) 053 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file ...