CVE-2019-6292 PUBLISHED

An issue was discovered in singledocparser.cpp in yaml-cpp (aka LibYaml-C++) 0.6.2. Stack Exhaustion occurs in YAML::SingleDocParser, and there is a stack consumption problem caused by recursive stack frames: HandleCompactMap, HandleMap, HandleFlowSequence, HandleSequence, HandleNode. Remote attackers could leverage this vulnerability to cause a denial-of-service via a cpp file.

EPSS 0.59% · 69.1th percentile

Risk Scores

EPSS Score
0.59%
69.1th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSyaml-cpp0, 0.6.2-4ubuntu1, 0.6.2-4fakesync1
Ubuntu:16.04:LTSyaml-cpp0, 0.5.2-4ubuntu1~16.04.4, 0.5.2-2
Ubuntu:14.04:LTSyaml-cpp0.5.1-1, 0, 0.3.0-1
Ubuntu:16.04:LTSyaml-cpp0.30.3.0-1.2, 0
Ubuntu:18.04:LTSyaml-cpp0.30, 0.3.0-1.2
Ubuntu:18.04:LTSyaml-cpp0.5.2-4ubuntu1, 0

Timeline

References

Open in Interactive Console →