Candidate: CVE-2019-1010182 PublicDate: 2019-07-25 14:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010182 https://github.com/chyh1990/yaml-rust/pull/109 Description: yaml-rust 0.4.0 and earlier is affected by: Uncontrolled Recursion. The impact is: Denial of service by impossible to catch abort. The component is: YamlLoader::load_from_str function. The attack vector is: Parsing of a malicious YAML document. The fixed version is: 0.4.1 and later. Ubuntu-Description: Notes: Bugs: Priority: untriaged Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_rust-yaml-rust: upstream_rust-yaml-rust: not-affected (debian: Fixed before initial release to Debian) precise/esm_rust-yaml-rust: DNE trusty_rust-yaml-rust: ignored (out of standard support) trusty/esm_rust-yaml-rust: DNE xenial_rust-yaml-rust: DNE bionic_rust-yaml-rust: DNE disco_rust-yaml-rust: not-affected (0.4.2-1) devel_rust-yaml-rust: not-affected (0.4.2-1)