CVE-2014-9130: Input Validation
Published Dec 8, 2014
·Updated
scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping.
Affected Software
2 affected components
PyYAML Libyaml=0.1.5
PyYAML Libyaml=0.1.6
Event History
Dec 8, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9130?
CVE-2014-9130 has a moderate severity level as it can lead to denial of service (DoS) due to assertion failure and crash.
2
How do I fix CVE-2014-9130?
To fix CVE-2014-9130, you should upgrade LibYAML to version 0.1.7 or later where the vulnerability has been addressed.
3
What software versions are affected by CVE-2014-9130?
CVE-2014-9130 affects LibYAML versions 0.1.5 and 0.1.6.
4
What type of attack is possible with CVE-2014-9130?
CVE-2014-9130 allows context-dependent attackers to launch a denial of service attack through specific line-wrapping inputs.
5
Is CVE-2014-9130 present in any other software besides LibYAML?
CVE-2014-9130 specifically affects LibYAML and does not apply to other software directly.