CVE Vulnerabilities

CVE-2024-35328

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jun 13, 2024 | Modified: Jul 19, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

libyaml v0.2.5 is vulnerable to DDOS. Affected by this issue is the function yaml_parser_parse of the file /src/libyaml/src/parser.c.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Libyaml Pyyaml 0.2.5 (including) 0.2.5 (including)
Golang-yaml.v2 Ubuntu mantic *
Libyaml Ubuntu mantic *
Libyaml-libyaml-perl Ubuntu mantic *

References