Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 28 Aug 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Pyyaml
Pyyaml libyaml |
|
| References |
|
Wed, 28 Aug 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libyaml v0.2.5 is vulnerable to a denial of service. Affected by this issue is the function yaml_parser_parse of the file /src/libyaml/src/parser.c. NOTE: this is disputed by the supplier because the discoverer's sample C code is incorrect: it does not call required _initialize functions that are described in the LibYAML documentation. | DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. |
Wed, 28 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 Aug 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libyaml v0.2.5 is vulnerable to DDOS. Affected by this issue is the function yaml_parser_parse of the file /src/libyaml/src/parser.c. | libyaml v0.2.5 is vulnerable to a denial of service. Affected by this issue is the function yaml_parser_parse of the file /src/libyaml/src/parser.c. NOTE: this is disputed by the supplier because the discoverer's sample C code is incorrect: it does not call required _initialize functions that are described in the LibYAML documentation. |
Wed, 28 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Subscriptions
No data.
Status: REJECTED
Assigner: mitre
Published:
Updated: 2024-08-28T15:40:05.988Z
Reserved: 2024-05-17T00:00:00.000Z
Link: CVE-2024-35328
Updated:
Status : Rejected
Published: 2024-06-13T16:15:11.037
Modified: 2024-08-28T16:15:08.863
Link: CVE-2024-35328
OpenCVE Enrichment
No data.