RUSTSEC-2018-0006: yaml-rust: Uncontrolled recursion leads to abort in deserialization

Description

Affected versions of this crate did not prevent deep recursion while deserializing data structures.

This allows an attacker to make a YAML file with deeply nested structures that causes an abort while deserializing it.

The flaw was corrected by checking the recursion depth.

More Info

https://github.com/chyh1990/yaml-rust/pull/109

Patched Versions