CVE-2025-11683

⚪ Do wiadomości

Brak terminatorów null w YAML::Syck umożliwia odczyt danych poza przydzieloną pamięcią.

CVSS
6.5
EPSS
0.3%
Exploit
none
Vendor
toddr
Opis źródłowy (NVD)

YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure Missing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to be read The issue is seen with complex YAML files with a hash of all keys and empty values.  There is no indication that the issue leads to accessing memory outside that allocated to the module.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2025-10-16 01:15:32 UTC
Ostatnia modyfikacja (NVD)2026-10-08 11:10:00 UTC
Referencje