CVE-2013-6393

Priority
Medium
Description
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5
performs an incorrect cast, which allows remote attackers to cause a denial
of service (application crash) and possibly execute arbitrary code via
crafted tags in a YAML document, which triggers a heap-based buffer
overflow.
References
Bugs
Notes
mdeslaur> regression was introduced in USN-2098-1
mdeslaur> redhat created three patches:
mdeslaur> libyaml-string-overflow.patch is upstream
mdeslaur> 1d73f004f49e6962cf936da98aecf0aec95c4c50
mdeslaur> libyaml-node-id-hardening.patch seems to have been done
mdeslaur> differently upstream in b77d42277c32b58a114a0fa0968038a4b0ab24f4
mdeslaur> libyaml-indent-column-overflow-v2.patch was done differently
mdeslaur> upstream in f859ed1eb757a3562b98a28a8ce69274bfd4b3f2 and
mdeslaur> af3599437a87162554787c52d8b16eab553f537b
Assigned-to
mdeslaur
Package
Upstream:needed
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):released (0.38-2ubuntu0.1)
Ubuntu 12.10 (Quantal Quetzal):released (0.38-3ubuntu0.12.10.1)
Ubuntu 13.10 (Saucy Salamander):released (0.38-3ubuntu0.13.10.1)
Ubuntu 14.04 LTS (Trusty Tahr):not-affected (0.41-5)
Package
Upstream:released (0.1.5)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):released (0.1.4-2ubuntu0.12.04.1)
Ubuntu 12.10 (Quantal Quetzal):released (0.1.4-2ubuntu0.12.10.1)
Ubuntu 13.10 (Saucy Salamander):released (0.1.4-2ubuntu0.13.10.1)
Ubuntu 14.04 LTS (Trusty Tahr):released (0.1.4-3ubuntu1)
Patches:
Upstream:https://bitbucket.org/xi/libyaml/commits/1d73f004f49e6962cf936da98aecf0aec95c4c50
Upstream:https://bitbucket.org/xi/libyaml/commits/b77d42277c32b58a114a0fa0968038a4b0ab24f4
Upstream:https://bitbucket.org/xi/libyaml/commits/f859ed1eb757a3562b98a28a8ce69274bfd4b3f2
Upstream:https://bitbucket.org/xi/libyaml/commits/0df2fb962294f3a6df1450a3e08c6a0f74f9078c
Upstream:https://bitbucket.org/xi/libyaml/commits/af3599437a87162554787c52d8b16eab553f537b
More Information

Valid XHTML 1.0 Strict

Updated: 2014-04-03 15:14:36 UTC (commit 7909)