SB2025111488 - openEuler 22.03 LTS SP4 update for yaml-cpp
Published: November 14, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Reachable Assertion (CVE-ID: CVE-2017-11692)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion in the Token& Scanner::peek() function in scanner.cpp in yaml-cpp. A remote attacker can send a specially crafted !2 string and perform a denial of service attack.
Remediation
Install update from vendor's website.