CVE-2019-25777: YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution
YAML versions before 1.27001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution.
A perl/glob document names a package and a symbol, and supplies the value assigned to it. Nothing restricts the name, so the target can be @INC or YAML's own load options.
A perl/glob document that sets $YAML::LoadCode or $YAML::UseCode turns on code loading, which is off by default, for every later Load() in the process. A perl/code document is then passed to a string eval, so an attacker who supplies two documents to separate Load() calls in one process can execute arbitrary Perl code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
YAML (Perl)to a version that resolves this vulnerability.Fixed in 1.28
Event History
Frequently Asked Questions
Which applications are realistically exposed?
Applications that call YAML Load() on attacker-supplied YAML are exposed if the vulnerable Perl YAML version is in use. Exploitation requires the attacker-controlled documents to be loaded within the same process.
Does the default code-loading setting prevent exploitation?
No. Although code loading is off by default, a perl/glob document can set $YAML::LoadCode or $YAML::UseCode and enable it for later Load() calls in that process.
What does an attacker need to provide to achieve code execution?
The attacker needs to provide a perl/glob document that changes a package variable, followed by a perl/code document passed to a later Load() call in the same process. The second document is evaluated with string eval after code loading has been enabled.
What should be done if the application cannot be updated immediately?
Do not pass untrusted YAML to Load(), particularly where multiple attacker-controlled documents may be processed by the same Perl process. Prevent perl/glob documents from reaching the loader, since they can modify package variables including YAML load options.
How can I determine whether the installed library is affected?
Versions before 1.27_001 are affected. Review the installed Perl YAML package version and identify whether the application loads untrusted YAML or performs multiple Load() calls in a shared process.