Bugzilla – Bug 1203154
VUL-0: CVE-2022-38752: snakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCode
Last modified: 2024-04-19 14:04:35 UTC
CVE-2022-38752 Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-38752 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47081 https://www.cve.org/CVERecord?id=CVE-2022-38752 https://bitbucket.org/snakeyaml/snakeyaml/issues/531/stackoverflow-oss-fuzz-47081
This one is still not fixed upstream. Tracking as affected: - SUSE:SLE-15-SP2:Update - SUSE:SLE-15-SP2:Update:Products:Manager41:Update - openSUSE:Factory
SUSE-SU-2022:3397-1: An update that fixes 6 vulnerabilities is now available. Category: security (important) Bug References: 1202932,1203149,1203153,1203154,1203158 CVE References: CVE-2020-13936,CVE-2022-25857,CVE-2022-38749,CVE-2022-38750,CVE-2022-38751,CVE-2022-38752 JIRA References: Sources used: openSUSE Leap 15.4 (src): snakeyaml-1.31-150200.3.8.1 openSUSE Leap 15.3 (src): snakeyaml-1.31-150200.3.8.1 SUSE Linux Enterprise Module for SUSE Manager Server 4.3 (src): snakeyaml-1.31-150200.3.8.1 SUSE Linux Enterprise Module for SUSE Manager Server 4.2 (src): snakeyaml-1.31-150200.3.8.1 SUSE Linux Enterprise Module for Development Tools 15-SP4 (src): snakeyaml-1.31-150200.3.8.1 SUSE Linux Enterprise Module for Development Tools 15-SP3 (src): snakeyaml-1.31-150200.3.8.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:3560-1: An update that fixes 6 vulnerabilities is now available. Category: security (important) Bug References: 1183360,1202932,1203149,1203153,1203154,1203158 CVE References: CVE-2020-13936,CVE-2022-25857,CVE-2022-38749,CVE-2022-38750,CVE-2022-38751,CVE-2022-38752 JIRA References: Sources used: SUSE Linux Enterprise Module for SUSE Manager Server 4.1 (src): snakeyaml-1.31-150200.12.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
done