MGASA-2014-0154

Source
https://advisories.mageia.org/MGASA-2014-0154.html
Import Source
https://advisories.mageia.org/MGASA-2014-0154.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0154
Related
Published
2014-04-03T01:02:12Z
Modified
2014-04-03T01:01:59Z
Summary
Updated perl-YAML-LibYAML package fixes security vulnerabilies
Details

Updated perl-YAML-LibYAML packages fix security vulnerabilities:

Florian Weimer of the Red Hat Product Security Team discovered a heap-based buffer overflow flaw in LibYAML, a fast YAML 1.1 parser and emitter library. A remote attacker could provide a YAML document with a specially-crafted tag that, when parsed by an application using libyaml, would cause the application to crash or, potentially, execute arbitrary code with the privileges of the user running the application (CVE-2013-6393).

Ivan Fratric of the Google Security Team discovered a heap-based buffer overflow vulnerability in LibYAML, a fast YAML 1.1 parser and emitter library. A remote attacker could provide a specially-crafted YAML document that, when parsed by an application using libyaml, would cause the application to crash or, potentially, execute arbitrary code with the privileges of the user running the application (CVE-2014-2525).

The perl-YAML-LibYAML package is being updated as it contains an embedded copy of LibYAML.

References
Credits

Affected packages

Mageia:4 / perl-YAML-LibYAML

Package

Name
perl-YAML-LibYAML
Purl
pkg:rpm/mageia/perl-YAML-LibYAML?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.410.0-2.2.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:3 / perl-YAML-LibYAML

Package

Name
perl-YAML-LibYAML
Purl
pkg:rpm/mageia/perl-YAML-LibYAML?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.380.0-3.2.mga3

Ecosystem specific

{
    "section": "core"
}