Candidate: CVE-2017-5950 PublicDate: 2017-04-03 05:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5950 Description: The SingleDocParser::HandleNode function in yaml-cpp (aka LibYaml-C++) 0.5.3 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file. Ubuntu-Description: Notes: leosilva> by https://github.com/jbeder/yaml-cpp/issues/650 it seems leosilva> fix in issue #459 is incomplete. Bugs: https://github.com/jbeder/yaml-cpp/issues/459 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=859891 Priority: negligible Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_yaml-cpp0.3: upstream_yaml-cpp0.3: needed precise_yaml-cpp0.3: DNE precise/esm_yaml-cpp0.3: DNE trusty_yaml-cpp0.3: ignored (reached end-of-life) trusty/esm_yaml-cpp0.3: DNE (trusty was needed) vivid/stable-phone-overlay_yaml-cpp0.3: DNE vivid/ubuntu-core_yaml-cpp0.3: DNE xenial_yaml-cpp0.3: ignored (end of standard support, was needed) yakkety_yaml-cpp0.3: ignored (reached end-of-life) zesty_yaml-cpp0.3: ignored (reached end-of-life) artful_yaml-cpp0.3: ignored (reached end-of-life) bionic_yaml-cpp0.3: needed cosmic_yaml-cpp0.3: ignored (reached end-of-life) disco_yaml-cpp0.3: DNE eoan_yaml-cpp0.3: DNE focal_yaml-cpp0.3: DNE groovy_yaml-cpp0.3: DNE hirsute_yaml-cpp0.3: DNE impish_yaml-cpp0.3: DNE jammy_yaml-cpp0.3: DNE devel_yaml-cpp0.3: DNE Patches_yaml-cpp: upstream_yaml-cpp: released (0.6.3-1) precise_yaml-cpp: DNE precise/esm_yaml-cpp: DNE trusty_yaml-cpp: ignored (out of standard support) trusty/esm_yaml-cpp: deferred (2019-10-01) vivid/stable-phone-overlay_yaml-cpp: DNE vivid/ubuntu-core_yaml-cpp: DNE xenial_yaml-cpp: ignored (end of standard support, was needed) yakkety_yaml-cpp: ignored (reached end-of-life) zesty_yaml-cpp: ignored (reached end-of-life) artful_yaml-cpp: ignored (reached end-of-life) bionic_yaml-cpp: needed cosmic_yaml-cpp: ignored (reached end-of-life) disco_yaml-cpp: ignored (reached end-of-life) eoan_yaml-cpp: ignored (reached end-of-life) focal_yaml-cpp: needed groovy_yaml-cpp: not-affected (0.6.3-9) hirsute_yaml-cpp: not-affected (0.6.3-9) impish_yaml-cpp: not-affected (0.6.3-9) jammy_yaml-cpp: not-affected (0.6.3-9) devel_yaml-cpp: not-affected (0.6.3-9)