CVE-2019-6285 is a denial-of-service vulnerability affecting yaml-cpp (aka LibYaml-C++) version 0.6.2, specifically within the SingleDocParser::HandleFlowSequence function. This flaw allows remote attackers to trigger a stack consumption and application crash through a specially crafted YAML file. With a CVSS score of 6.5 (MEDIUM), it has a low attack complexity and requires user interaction, but can lead to high availability impact. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.6.2CPE matchmatch criteria | cpe:2.3:a:yaml-cpp_project:yaml-cpp:0.6.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
yaml-cpp: DoS in SingleDocParser::HandleFlowSequence funtion
Jan 14, 2019The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.
Jan 8, 2019