Executive brief
libyaml is a library used to parse YAML configuration files across many applications. A heap buffer overflow in versions 0.1.5 and earlier allows attackers to crash applications or execute arbitrary code by providing specially crafted YAML files with malicious tags.
Technical details
A heap-based buffer overflow exists in the YAML tag parsing logic of libyaml versions 0.1.5 and earlier (affecting npm libyaml 0.2.2 and earlier). The vulnerability resides in how the library handles YAML tags during parsing. An attacker can trigger the overflow by providing a malicious YAML document with specially crafted tags, which can lead to a crash (denial of service) or arbitrary code execution. The attack requires providing a malicious YAML file as input; no authentication is required. The fix is available in libyaml version 0.2.3 for npm and in the corresponding upstream libyaml release.
Affected products
- libyaml libyaml 0.2.2 and earlier
Timeline
- 2013: disclosed: CVE-2013-6393 assigned; vulnerability in libyaml 0.1.5 and earlier
- 2013: patched: Fix released in libyaml; npm libyaml 0.2.3 includes patched libyaml
- 2020-08-31: advisory: GHSA-m75h-cghq-c8h5 published to GitHub advisory database