yaml / libyaml

Canonical source repository for LibYAML
http://pyyaml.org/wiki/LibYAML
MIT License
969 stars 325 forks source link

CVE-2024-35326, CVE-2024-35328, CVE-2024-35329 #302

Open perlpunk opened 4 months ago

perlpunk commented 4 months ago

The following CVEs I do not consider as vulnerabilties:

They are all missing to initialize structs with the according proper functions for that, so there doesn't exist any working code that could be exploited. I already contacted mitre.org for CVE-2024-35329 over a month ago to reject this, but no reply :(

There has already been some discussion in #298 but I decided to create a new issue because the thread is hard to read because of the discussion of how those CVEs were (not) reported and published.

hasufell commented 4 months ago

I'm starting to think someone is abusing the CVE process to spam maintainers with low quality bug reports.

zhuofeng6 commented 4 months ago

CVE-2024-35326, CVE-2024-35328 Did these two cve rejects, to nvd

rsbeckerca commented 3 months ago

Other projects have experienced this spam. Mitre responded appropriately to one in curl (IIRC) but they seem to act very slowly.

rsbeckerca commented 3 months ago

I have a pull request #305 that might close out issues with #302, specifically CVE-2024-35326. Even with the reject, a little defensive coding rarely hurts.

openmorse commented 3 months ago

The above CVEs are REJECTED now (not security issues) https://www.cve.org/CVERecord?id=CVE-2024-35326 https://www.cve.org/CVERecord?id=CVE-2024-35328 https://www.cve.org/CVERecord?id=CVE-2024-35329