CVE-2013-6393

Impact:
Moderate
Public Date:
2014-01-27
CWE:
CWE-122
Bugzilla:
1033990: CVE-2013-6393 libyaml: heap-based buffer overflow when parsing YAML tags

The MITRE CVE dictionary describes this issue as:

The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.

Find out more about CVE-2013-6393 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

The Red Hat security response team has rated this issue as having low security impact in Red Hat Enterpise MRG 1 and 2, CloudForms 3, and Red Hat Network Satellite 5. This issue is not currently planned to be addressed in future updates.

The Red Hat security response team has rated this issue as having low security impact in Red Hat Update Infrastructure. A future update may address this issue.

The Red Hat security response team has rated this issue as having moderate security impact in Subscription Asset Manager 1. A future update may address this issue.

For additional information, refer to the Issue Severity Classification:
https://access.redhat.com/security/updates/classification/

CVSS v2 metrics

Base Score 4.3
Base Metrics AV:A/AC:H/Au:N/C:P/I:P/A:P
Access Vector Adjacent Network
Access Complexity High
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux OpenStack Platform 4.0 (libyaml) RHSA-2014:0354 2014-04-02
Red Hat Enterprise Linux OpenStack Platform 3.0 (libyaml) RHSA-2014:0353 2014-04-02
Red Hat Common for Red Hat Enterprise Linux 6 (libyaml) RHSA-2014:0415 2014-04-17
Red Hat Enterprise Linux OpenStack Platform 3.0 (ruby193-libyaml) RHSA-2014:0364 2014-04-03
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 (ruby193-libyaml) RHSA-2014:0355 2014-04-02

Affected Packages State

Platform Package State
Red Hat Subscription Asset Manager 1 libyaml Will not fix
Red Hat Software Collections 1 for Red Hat Enterprise Linux libyaml Will not fix
Red Hat Satellite 6 ruby193-libyaml Will not fix
Red Hat Satellite 6 libyaml Will not fix
Red Hat Satellite 5.6 libyaml Will not fix
Red Hat Satellite 5.5 libyaml Will not fix
Red Hat Satellite 5.4 libyaml Will not fix
Red Hat Satellite 5.3 libyaml Will not fix
Red Hat OpenShift Enterprise 1 ruby193-libyaml Will not fix
Red Hat Enterprise MRG 2 libyaml Will not fix
Red Hat Enterprise MRG 1 libyaml Will not fix
Red Hat Enterprise Linux 7 libyaml Not affected
Red Hat Enterprise Linux 6 libyaml Will not fix

Acknowledgements

This issue was discovered by Florian Weimer of the Red Hat Product Security Team.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.