MGASA-2014-0508

Source
https://advisories.mageia.org/MGASA-2014-0508.html
Import Source
https://advisories.mageia.org/MGASA-2014-0508.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0508
Related
Published
2014-12-05T15:54:13Z
Modified
2014-12-05T15:46:26Z
Summary
Updated yaml & perl-YAML-LibYAML packages fix CVE-2014-9130
Details

Updated yaml and perl-YAML-LibYAML packages fix security vulnerability:

An assertion failure was found in the way the libyaml library parsed wrapped strings. An attacker able to load specially crafted YAML input into an application using libyaml could cause the application to crash (CVE-2014-9130).

The perl-YAML-LibYAML package is also affected, as it was derived from the same code. Both have been patched to fix this issue.

References
Credits

Affected packages

Mageia:4 / yaml

Package

Name
yaml
Purl
pkg:rpm/mageia/yaml?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.1.6-1.1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / perl-YAML-LibYAML

Package

Name
perl-YAML-LibYAML
Purl
pkg:rpm/mageia/perl-YAML-LibYAML?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.410.0-2.3.mga4

Ecosystem specific

{
    "section": "core"
}