Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LibYAML ‘yaml_parser_scan_tag_uri’函数基于堆的缓冲区溢出漏洞
Vulnerability Description
LibYAML是Kirill Simonov程序员所研发的一个用于解析YAML 1.1数据的C语言包。 LibYAML 0.1.4及之前的版本中的scanner.c文件中的‘yaml_parser_scan_tag_uri’函数中存在基于堆的缓冲区溢出漏洞。当解析YAML标签时,远程攻击者可通过特制的YAML文档利用该漏洞造成拒绝服务(应用程序崩溃),也可能执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A