Bug 2545818 (CVE-2019-25777) - CVE-2019-25777 perl-yaml: perl-yaml: Arbitrary code execution via unrestricted package variable assignment
Summary: CVE-2019-25777 perl-yaml: perl-yaml: Arbitrary code execution via unrestricte...
Keywords:
Status: NEW
Alias: CVE-2019-25777
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-05 07:08 UTC by OSIDB Bzimport
Modified: 2026-10-06 08:09 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-05 07:08:34 UTC
YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution.

A perl/glob document names a package and a symbol, and supplies the value assigned to it. Nothing restricts the name, so the target can be @INC or YAML's own load options.

A perl/glob document that sets $YAML::LoadCode or $YAML::UseCode turns on code loading, which is off by default, for every later Load() in the process. A perl/code document is then passed to a string eval, so an attacker who supplies two documents to separate Load() calls in one process can execute arbitrary Perl code.


Note You need to log in before you can comment on or make changes to this bug.