Bugzilla – Bug 1203149
VUL-0: CVE-2022-38749: snakeyaml: StackOverflowError for many open unmatched brackets
Last modified: 2022-10-11 13:21:41 UTC
CVE-2022-38749 Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. Upstream fix: https://github.com/snakeyaml/snakeyaml/commit/fc300780da21f4bb92c148bc90257201220cf174 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-38749 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47024 https://www.cve.org/CVERecord?id=CVE-2022-38749 https://bitbucket.org/snakeyaml/snakeyaml/issues/525/got-stackoverflowerror-for-many-open
Affected: - SUSE:SLE-15-SP2:Update - SUSE:SLE-15-SP2:Update:Products:Manager41:Update
SUSE-SU-2022:3397-1: An update that fixes 6 vulnerabilities is now available. Category: security (important) Bug References: 1202932,1203149,1203153,1203154,1203158 CVE References: CVE-2020-13936,CVE-2022-25857,CVE-2022-38749,CVE-2022-38750,CVE-2022-38751,CVE-2022-38752 JIRA References: Sources used: openSUSE Leap 15.4 (src): snakeyaml-1.31-150200.3.8.1 openSUSE Leap 15.3 (src): snakeyaml-1.31-150200.3.8.1 SUSE Linux Enterprise Module for SUSE Manager Server 4.3 (src): snakeyaml-1.31-150200.3.8.1 SUSE Linux Enterprise Module for SUSE Manager Server 4.2 (src): snakeyaml-1.31-150200.3.8.1 SUSE Linux Enterprise Module for Development Tools 15-SP4 (src): snakeyaml-1.31-150200.3.8.1 SUSE Linux Enterprise Module for Development Tools 15-SP3 (src): snakeyaml-1.31-150200.3.8.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:3560-1: An update that fixes 6 vulnerabilities is now available. Category: security (important) Bug References: 1183360,1202932,1203149,1203153,1203154,1203158 CVE References: CVE-2020-13936,CVE-2022-25857,CVE-2022-38749,CVE-2022-38750,CVE-2022-38751,CVE-2022-38752 JIRA References: Sources used: SUSE Linux Enterprise Module for SUSE Manager Server 4.1 (src): snakeyaml-1.31-150200.12.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.