Missing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to be read
The issue is seen with complex YAML files with a hash of all keys and empty values. There is no indication that the issue leads to accessing memory outside that allocated to the module.
No advisories yet.
Solution
Upgrade to version 1.36 or higher
Workaround
Apply the patch
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Perl
Perl perl Perl yaml::syck |
|
| Vendors & Products |
Perl
Perl perl Perl yaml::syck |
Fri, 17 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 16 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 16 Oct 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure Missing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to be read The issue is seen with complex YAML files with a hash of all keys and empty values. There is no indication that the issue leads to accessing memory outside that allocated to the module. | |
| Title | YAML::Syck versions before 1.36 for Perl has missing Null-Terminators which causes Out-of-Bounds Read and potential Information Disclosure | |
| Weaknesses | CWE-119 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2025-10-16T13:42:17.584Z
Reserved: 2025-10-13T12:35:07.822Z
Link: CVE-2025-11683
Updated: 2025-10-16T13:42:05.706Z
Status : Awaiting Analysis
Published: 2025-10-16T01:15:32.890
Modified: 2025-10-16T15:28:59.610
Link: CVE-2025-11683
OpenCVE Enrichment
Updated: 2025-10-21T09:40:49Z