CVE Vulnerabilities

CVE-2024-35329

Published: Jun 11, 2024 | Modified: Jun 12, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N
Ubuntu
MEDIUM

libyaml 0.2.5 is vulnerable to a heap-based Buffer Overflow in yaml_document_add_sequence in api.c. NOTE: the supplier disputes this because the finding represents a user error. The problem is that the application, which was making use of the libyaml library, omitted the required calls to the yaml_document_initialize and yaml_document_delete functions.

Affected Software

Name Vendor Start Version End Version
Golang-yaml.v2 Ubuntu mantic *
Libyaml Ubuntu mantic *
Libyaml-libyaml-perl Ubuntu mantic *

References