Stack-based buffer overflow in Snakeyaml - CVE-2022-38750

 

Stack-based buffer overflow in Snakeyaml - CVE-2022-38750

Published: September 27, 2022


Vulnerability identifier: #VU67668
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-38750
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when handling YAML files. A remote attacker can pass a specially crafted YAML file to the application, trigger a stack-based buffer overflow and perform a denial of service (DoS) attack.

Affected software

Snakeyaml
Amazon Linux AMI
Gentoo Linux
SUSE Manager Server
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Storage
Fedora
Ubuntu
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
openEuler
WebSphere Service Registry and Repository
IBM Cloud Transformation Advisor
Log Analysis
Netcool Operations Insight
IBM Cloud Pak for Multicloud Management Monitoring
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
Red Hat Satellite
IBM Spectrum Symphony
IBM Maximo Application Suite
IBM MQ
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
DB2 Warehouse on Cloud Pak for Data
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
IBM Watson Machine Learning Accelerator
Integration Designer
Db2 Graph
PowerStore X
PowerStore T
Robotic Process Automation for Cloud Pak
IBM Data Risk Manager
Cloudera Data Platform Private Cloud Base for IBM
Vert.x
SecureTransport
Red Hat Single Sign-On
AMQ Broker
JBoss Data Grid
IBM App Connect Enterprise
Red Hat Camel for Spring Boot
libyaml-snake-java (Ubuntu package)
snakeyaml
snakeyaml-javadoc
dev-java/snakeyaml
rh-sso7-keycloak (Red Hat package)
Voice Gateway
watsonx.data
Operational Decision Manager
IBM DB2
IBM InfoSphere Information Server

How to mitigate CVE-2022-38750

Install updates from vendor's website.

Snakeyaml - update to 1.31
IBM Cloud Transformation Advisor - update to 3.4.0
IBM Data Risk Manager - update to 2.0.6.15
Vert.x - update to 4.3.3
SecureTransport - update to 5.5-20220929
Cloudera Data Platform Private Cloud Base for IBM - addressed in versions 7.1.7 SP3, 7.1.9 SP1
Red Hat Single Sign-On - update to 7.6.2
AMQ Broker - update to 7.10.2
JBoss Data Grid - update to 8.4.0
libyaml-snake-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.23-1+deb10u1build0.18.04.1, 1.25+ds-2ubuntu0.1, 1.29-1ubuntu0.22.04.1, 1.29-1ubuntu0.22.10.1
Db2 Graph - addressed in versions 1.0.0.1562-amd64, 1.0.0.1562-s390x, 1.0.0.1562-ppcle, 1.0.0.1598-amd64, 1.0.0.1598-s390x, 1.0.0.1598-ppcle
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
Log Analysis - update to 1.3.7.2 IF003A
Netcool Operations Insight - update to 1.6.10
snakeyaml - update to 1.27-6
snakeyaml-javadoc - update to 1.31-150200.3.8.1
snakeyaml - addressed in versions 1.31-150200.3.8.1, 1.31-150200.12.6.1
snakeyaml-javadoc - update to 1.32-1
snakeyaml - update to 1.32-1
snakeyaml - addressed in versions 1.32-1.el8, 1.32-1.el9
dev-java/snakeyaml - update to 1.33
watsonx.data - update to 2.0
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 6
PowerStore X - update to 3.2.1.0-1989710
PowerStore T - update to 3.2.1.0-1989710
Red Hat Camel for Spring Boot - addressed in versions 3.18.3 Patch 2, 3.20.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.0
App Connect Enterprise Certified Container - addressed in versions 5.0.2, 6.2.0
IBM Sterling B2B Integrator - addressed in versions 6.0.3.8, 6.1.2.1
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.9, 6.2.2.2
Red Hat Satellite - update to 6.13
IBM Spectrum Symphony - update to 7.3.2 Fix 601711
IBM Maximo Application Suite - addressed in versions 8.9.6, 8.10.4
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
IBM MQ - addressed in versions 9.2.0.7, 9.3.0.1, 9.3.1
IBM DB2 - update to 11.1.4.7
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
rh-sso7-keycloak (Red Hat package) - addressed in versions 18.0.6-1.redhat_00001.1.el7sso, 18.0.6-1.redhat_00001.1.el8sso, 18.0.6-1.redhat_00001.1.el9sso
IBM Business Automation Workflow - addressed in versions 20.0.0.2, 21.0.3, 21.0.3 IF015, 22.0.1, 22.0.1 IF005
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.18, 22.0.2.2
Robotic Process Automation for Cloud Pak - update to 21.0.6

External References

Related Security Bulletins