RUSTSEC-2018-0006
Dashboard / Vulnerabilities / RUSTSEC-2018-0006
RUSTSEC-2018-0006
Summary: Uncontrolled recursion leads to abort in deserialization
Details: Affected versions of this crate did not prevent deep recursion while deserializing data structures. This allows an attacker to make a YAML file with deeply nested structures that causes an abort while deserializing it. The flaw was corrected by checking the recursion depth. Note: `clap 2.33` is not affected by this because it uses `yaml-rust` in a way that doesn't trigger the vulnerability. More specifically: 1. The input to the YAML parser is always trusted - is included at compile time via `include_str!`. 2. The nesting level is never deep enough to trigger the overflow in practice (at most 5).
References: https://crates.io/crates/yaml-rust, https://rustsec.org/advisories/RUSTSEC-2018-0006.html, https://github.com/chyh1990/yaml-rust/pull/109
Affected packages
Package
Name: yaml-rust
Purl: pkg:cargo/yaml-rust
Affected ranges
Type: SEMVER
Events:
