suse · CVE-2017-5950

Quick triage

Priority: medium Published: 2021-05-30 13:53:14 UTC Updated: 2026-04-18 09:11:55 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-5950 severity moderate: SUSE including 249 source package names (amazon/suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64, amazon/suse-sles-15-sp1-chost-byos-v20220127-hvm-ssd-x86_64, …), 304 product×package rows across 50 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (50 product lines)): Known Affected 157, Fixed 111, Known Not Affected 36.

Description:

The SingleDocParser::HandleNode function in yaml-cpp (aka LibYaml-C++) 0.5.3 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.

cvelogic Threat Intelligence