HTTP: LibYAML Scanner yaml_parser_scan_uri_escapes Heap Buffer Overflow
This signature detects attempts to exploit a known vulnerability in the LibYAML Scanner. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.
Extended Description
Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execute arbitrary code via a long sequence of percent-encoded characters in a URI in a YAML file.
Affected Products
Opensuse opensuse
References
CVE: CVE-2014-2525
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Pyyaml
Opensuse
6.8