suse · CVE-2018-20573

Quick triage

Priority: medium Published: 2021-05-30 14:19:44 UTC Updated: 2026-03-05 06:34:24 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-20573 severity moderate: SUSE including 287 source package names (0.21.0.1.8.13:libyaml-cpp0_6-0.6.1-4.5.1, 0.23.0.3.2.201:libyaml-cpp0_6-0.6.1-4.5.1, …), 354 product×package rows across 106 product lines (Container bci/bci-init, Container bci/golang, … (106 product lines)): Known Affected 181, Fixed 168, Known Not Affected 4, First Fixed 1.

Description:

The Scanner::EnsureTokensInQueue function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.

cvelogic Threat Intelligence