Cloud Foundry Logo
blog single gear
Security Advisory

CVE-2014-9130: LibYAML vulnerability

CVE-2014-9130: LibYAML vulnerability

Severity

Medium

Vendor

LibYAML

Versions Affected

  • Cloud Foundry Ruby Buildpack versions prior to 1.6.25

Description

Stanisław Pitucha and Jonathan Gray discovered that LibYAML did not properly handle wrapped strings. An attacker could create specially crafted YAML data to trigger an assert, causing a denial of service.

Mitigation

OSS users are strongly encouraged to follow one of the mitigations below:

  • Upgrade the Ruby Buildpack to v1.6.25 [1] or later and restage all applications that use automated buildpack detection

Credit

Stanisław Pitucha and Jonathan Gray

References

Cloud Foundry Foundation Security Team Profile Image

Cloud Foundry Foundation Security Team, AUTHOR

SEE ALL ARTICLES