CVE-2013-6393
published 2014-02-06CVE-2013-6393: The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of…
PriorityP340medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
9.31%
94.8th percentile
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libyaml | < libyaml 0.1.4-3 (bookworm) | libyaml 0.1.4-3 (bookworm) |
| debian | libyaml-libyaml-perl | < libyaml 0.1.4-3 (bookworm) | libyaml 0.1.4-3 (bookworm) |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| pyyaml | libyaml | <= 0.1.4 | — |
| pyyaml | libyaml | — | — |
| pyyaml | libyaml | — | — |
| pyyaml | libyaml | — | — |
| pyyaml | libyaml | — | — |
| pyyaml | libyaml | >= 0 < 0.1.4-3 | 0.1.4-3 |
| pyyaml | libyaml | >= 0 < 0.1.4-3 | 0.1.4-3 |
| pyyaml | libyaml | >= 0 < 0.1.4-3 | 0.1.4-3 |
| pyyaml | libyaml | >= 0 < 0.1.4-3 | 0.1.4-3 |
| pyyaml | libyaml | >= 0 < 0.2.3 | 0.2.3 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Heap Based Buffer Overflow in libyaml
osv·2020-08-31
CVE-2013-6393 [CRITICAL] Heap Based Buffer Overflow in libyaml
Heap Based Buffer Overflow in libyaml
Versions 0.2.2 and earlier depend on native libyaml version 0.1.5 or earlier. As such, they are affected by a heap-based buffer overflow vulnerability that may result in a crash or arbitrary code execution when parsing YAML tags.
## Recommendation
- Update to version 0.2.3 that includes a version of LibYAML that contains a fix for this issue.
GHSA
Heap Based Buffer Overflow in libyaml
ghsa·2020-08-31
CVE-2013-6393 [CRITICAL] CWE-119 Heap Based Buffer Overflow in libyaml
Heap Based Buffer Overflow in libyaml
Versions 0.2.2 and earlier depend on native libyaml version 0.1.5 or earlier. As such, they are affected by a heap-based buffer overflow vulnerability that may result in a crash or arbitrary code execution when parsing YAML tags.
## Recommendation
- Update to version 0.2.3 that includes a version of LibYAML that contains a fix for this issue.
OSV
CVE-2013-6393: The yaml_parser_scan_tag_uri function in scanner
osv·2014-02-06·CVSS 6.8
CVE-2013-6393 [MEDIUM] CVE-2013-6393: The yaml_parser_scan_tag_uri function in scanner
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.
Ubuntu
libyaml-libyaml-perl vulnerabilities
vendor_ubuntu·2014-04-03·CVSS 6.8
CVE-2013-6393 [MEDIUM] libyaml-libyaml-perl vulnerabilities
Title: libyaml-libyaml-perl vulnerabilities
Summary: libyaml-libyaml-perl could be made to crash or run programs if it opened a
specially crafted YAML file.
Florian Weimer discovered that libyaml-libyaml-perl incorrectly handled
certain large YAML documents. An attacker could use this issue to cause
libyaml-libyaml-perl to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2013-6393)
Ivan Fratric discovered that libyaml-libyaml-perl incorrectly handled
certain malformed YAML documents. An attacker could use this issue to cause
libyaml-libyaml-perl to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2014-2525)
Instructions: After a standard system update you need to restart applications using
libyaml-libyaml-perl to make al
Ubuntu
LibYAML vulnerability
vendor_ubuntu·2014-02-04
CVE-2013-6393 LibYAML vulnerability
Title: LibYAML vulnerability
Summary: LibYAML could be made to crash or run programs if it opened specially
crafted yaml document.
Florian Weimer discovered that LibYAML incorrectly handled certain large
yaml documents. An attacker could use this issue to cause LibYAML to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart applications using
LibYAML to make all the necessary changes.
Red Hat
libyaml: heap-based buffer overflow when parsing YAML tags
vendor_redhat·2014-01-27·CVSS 6.8
CVE-2013-6393 [MEDIUM] CWE-122 libyaml: heap-based buffer overflow when parsing YAML tags
libyaml: heap-based buffer overflow when parsing YAML tags
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.
A heap based buffer oveflow exists in the libyaml package such that a remote attacker could provide a specifically crafted YAML document when parsed by the application could result in remote code execution and complete compromise of the system.
Statement: The Red Hat security response team has rated this issue as having low security impact in Red Hat Enterpise MRG 1 and 2, CloudForms 3, and Red Hat Network Satellite 5. This issue is n
Debian
CVE-2013-6393: libyaml - The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 perfo...
vendor_debian·2013·CVSS 6.8
CVE-2013-6393 [MEDIUM] CVE-2013-6393: libyaml - The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 perfo...
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 0.1.4-3)
bullseye: resolved (fixed in 0.1.4-3)
forky: resolved (fixed in 0.1.4-3)
sid: resolved (fixed in 0.1.4-3)
trixie: resolved (fixed in 0.1.4-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6393 perl-YAML-LibYAML: libyaml: heap-based buffer overflow when parsing YAML tags [epel-6]
bugzilla·2014-03-27·CVSS 6.8
CVE-2013-6393 [MEDIUM] CVE-2013-6393 perl-YAML-LibYAML: libyaml: heap-based buffer overflow when parsing YAML tags [epel-6]
CVE-2013-6393 perl-YAML-LibYAML: libyaml: heap-based buffer overflow when parsing YAML tags [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Bugzilla
CVE-2013-6393 perl-YAML-LibYAML: libyaml: heap-based buffer overflow when parsing YAML tags [fedora-all]
bugzilla·2014-03-27·CVSS 6.8
CVE-2013-6393 [MEDIUM] CVE-2013-6393 perl-YAML-LibYAML: libyaml: heap-based buffer overflow when parsing YAML tags [fedora-all]
CVE-2013-6393 perl-YAML-LibYAML: libyaml: heap-based buffer overflow when parsing YAML tags [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Bugzilla
CVE-2013-6393 libyaml: heap-based buffer overflow when parsing YAML tags [epel-all]
bugzilla·2014-01-29·CVSS 6.8
CVE-2013-6393 [MEDIUM] CVE-2013-6393 libyaml: heap-based buffer overflow when parsing YAML tags [epel-all]
CVE-2013-6393 libyaml: heap-based buffer overflow when parsing YAML tags [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: thi
Bugzilla
CVE-2013-6393 libyaml: heap-based buffer overflow when parsing YAML tags [fedora-all]
bugzilla·2014-01-29·CVSS 6.8
CVE-2013-6393 [MEDIUM] CVE-2013-6393 libyaml: heap-based buffer overflow when parsing YAML tags [fedora-all]
CVE-2013-6393 libyaml: heap-based buffer overflow when parsing YAML tags [fedora-all]
+++ This bug was initially created as a clone of Bug #1059009 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM chan
Bugzilla
CVE-2013-6393 libyaml: heap-based buffer overflow when parsing YAML tags [fedora-all]
bugzilla·2014-01-29·CVSS 6.8
CVE-2013-6393 [MEDIUM] CVE-2013-6393 libyaml: heap-based buffer overflow when parsing YAML tags [fedora-all]
CVE-2013-6393 libyaml: heap-based buffer overflow when parsing YAML tags [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this i
Bugzilla
CVE-2013-6393 libyaml: heap-based buffer overflow when parsing YAML tags
bugzilla·2013-11-25·CVSS 6.8
CVE-2013-6393 [MEDIUM] CVE-2013-6393 libyaml: heap-based buffer overflow when parsing YAML tags
CVE-2013-6393 libyaml: heap-based buffer overflow when parsing YAML tags
A heap-based buffer overflow flaw was found in the way libyaml parsed YAML tags. A remote attacker could provide a specially-crafted YAML document that, when parsed by an application using libyaml, would cause the application to crash or, potentially, execute arbitrary code with the privileges of the user running the application.
Acknowledgements:
This issue was discovered by Florian Weimer of the Red Hat Product Security Team.
Discussion:
Created attachment 847926
String overflow patch
This is a proposed patch from Florian Weimer for the string
overflow issue. It has been ack'd by upstream.
---
Created attachment 847934
libyaml-node-id-hardening.patch
This is a hardening patch also from Florian Weimer .
It i
http://advisories.mageia.org/MGASA-2014-0040.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-04/0134.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-10/0103.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00064.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00065.htmlhttp://lists.opensuse.org/opensuse-updates/2015-02/msg00078.htmlhttp://lists.opensuse.org/opensuse-updates/2016-04/msg00050.htmlhttp://osvdb.org/102716http://rhn.redhat.com/errata/RHSA-2014-0353.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0354.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0355.htmlhttp://www.debian.org/security/2014/dsa-2850http://www.debian.org/security/2014/dsa-2870http://www.mandriva.com/security/advisories?name=MDVSA-2015:060http://www.securityfocus.com/bid/65258http://www.ubuntu.com/usn/USN-2098-1https://bitbucket.org/xi/libyaml/commits/tag/0.1.5https://bugzilla.redhat.com/attachment.cgi?id=847926&action=diffhttps://bugzilla.redhat.com/show_bug.cgi?id=1033990https://puppet.com/security/cve/cve-2013-6393https://support.apple.com/kb/HT6536http://advisories.mageia.org/MGASA-2014-0040.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-04/0134.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-10/0103.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00064.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00065.htmlhttp://lists.opensuse.org/opensuse-updates/2015-02/msg00078.htmlhttp://lists.opensuse.org/opensuse-updates/2016-04/msg00050.htmlhttp://osvdb.org/102716http://rhn.redhat.com/errata/RHSA-2014-0353.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0354.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0355.htmlhttp://www.debian.org/security/2014/dsa-2850http://www.debian.org/security/2014/dsa-2870http://www.mandriva.com/security/advisories?name=MDVSA-2015:060http://www.securityfocus.com/bid/65258http://www.ubuntu.com/usn/USN-2098-1https://bitbucket.org/xi/libyaml/commits/tag/0.1.5https://bugzilla.redhat.com/attachment.cgi?id=847926&action=diffhttps://bugzilla.redhat.com/show_bug.cgi?id=1033990https://puppet.com/security/cve/cve-2013-6393https://support.apple.com/kb/HT6536
2014-02-06
Published