Bug 1203158 - (CVE-2022-38750) VUL-0: CVE-2022-38750: snakeyaml: uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject.
(CVE-2022-38750)
VUL-0: CVE-2022-38750: snakeyaml: uncaught exception in org.yaml.snakeyaml.co...
Status: NEW
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/341525/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-09-06 09:36 UTC by Thomas Leroy
Modified: 2022-10-11 13:21 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2022-09-06 09:36:45 UTC
CVE-2022-38750

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of
Service attacks (DOS). If the parser is running on user supplied input, an
attacker may supply content that causes the parser to crash by stackoverflow.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-38750
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47027
https://www.cve.org/CVERecord?id=CVE-2022-38750
https://bitbucket.org/snakeyaml/snakeyaml/issues/526/stackoverflow-oss-fuzz-47027
Comment 3 Swamp Workflow Management 2022-09-26 19:29:36 UTC
SUSE-SU-2022:3397-1: An update that fixes 6 vulnerabilities is now available.

Category: security (important)
Bug References: 1202932,1203149,1203153,1203154,1203158
CVE References: CVE-2020-13936,CVE-2022-25857,CVE-2022-38749,CVE-2022-38750,CVE-2022-38751,CVE-2022-38752
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    snakeyaml-1.31-150200.3.8.1
openSUSE Leap 15.3 (src):    snakeyaml-1.31-150200.3.8.1
SUSE Linux Enterprise Module for SUSE Manager Server 4.3 (src):    snakeyaml-1.31-150200.3.8.1
SUSE Linux Enterprise Module for SUSE Manager Server 4.2 (src):    snakeyaml-1.31-150200.3.8.1
SUSE Linux Enterprise Module for Development Tools 15-SP4 (src):    snakeyaml-1.31-150200.3.8.1
SUSE Linux Enterprise Module for Development Tools 15-SP3 (src):    snakeyaml-1.31-150200.3.8.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 4 Swamp Workflow Management 2022-10-11 13:21:54 UTC
SUSE-SU-2022:3560-1: An update that fixes 6 vulnerabilities is now available.

Category: security (important)
Bug References: 1183360,1202932,1203149,1203153,1203154,1203158
CVE References: CVE-2020-13936,CVE-2022-25857,CVE-2022-38749,CVE-2022-38750,CVE-2022-38751,CVE-2022-38752
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for SUSE Manager Server 4.1 (src):    snakeyaml-1.31-150200.12.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.