HIGH7.5
GHSA-hv87-47h9-jcvq
Uncontrolled recursion in rust-yaml
Details
Affected versions of this crate did not prevent deep recursion while deserializing data structures. This allows an attacker to make a YAML file with deeply nested structures that causes an abort while deserializing it. The flaw was corrected by checking the recursion depth.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/yaml-rust
Introduced in:
0Fixed in: 0.4.1Upgrade yaml-rust to 0.4.1 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-20993[ADVISORY]
- https://github.com/chyh1990/yaml-rust/pull/109[WEB]
- https://github.com/chyh1990/yaml-rust/commit/d61b49cb90391fc4f7f72a1abe597476c8651a07[WEB]
- https://github.com/chyh1990/yaml-rust[PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2018-0006.html[WEB]