Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execute arbitrary code via a long sequence of percent-encoded characters in a URI in a YAML file.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DSA-2884-1 | libyaml security update |
![]() |
DSA-2885-1 | libyaml-libyaml-perl security update |
![]() |
USN-2160-1 | LibYAML vulnerability |
![]() |
USN-2161-1 | libyaml-libyaml-perl vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T10:14:26.613Z
Reserved: 2014-03-17T00:00:00
Link: CVE-2014-2525

No data.

Status : Deferred
Published: 2014-03-28T15:55:08.670
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-2525


No data.