CVE-2018-20573 describes a denial-of-service vulnerability in yaml-cpp (aka LibYaml-C++) version 0.6.2, where a specially crafted YAML file can cause a stack consumption and application crash. This vulnerability has a CVSS score of 6.5 (Medium), indicating it can be exploited remotely with low attack complexity, requiring user interaction, and leading to high availability impact. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.6.2CPE matchmatch criteria | cpe:2.3:a:yaml-cpp_project:yaml-cpp:0.6.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
yaml-cpp: DoS in Scanner::EnsureTokensInQueue function in yaml-cpp
Dec 28, 2018The Scanner::EnsureTokensInQueue function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.
Dec 11, 2018