Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:47566
HistoryJun 17, 2024 - 6:54 a.m.

Heap Buffer Overflow

2024-06-1706:54:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
libyaml
vulnerability
heap buffer overflow
initialization
emitter
code execution
developer error

AI Score

7.5

Confidence

High

EPSS

0

Percentile

9.6%

LibYAML is vulnerable to Heap buffer overflow. The vulnerability is due to the lack of proper initialization of the emitter when yaml_emitter_emit is called without yaml_emitter_initialize. An attacker can exploit this vulnerability by providing specially crafted inputs to trigger the overflow, potentially leading to arbitrary code execution. Note that there is no known exploit, and the vulnerability relies on a developer error when calling yaml_emitter_emit without yaml_emitter_initialize.

AI Score

7.5

Confidence

High

EPSS

0

Percentile

9.6%