MGASA-2014-0508
Dashboard / Vulnerabilities / MGASA-2014-0508
Summary: Updated yaml & perl-YAML-LibYAML packages fix CVE-2014-9130
Details: Updated yaml and perl-YAML-LibYAML packages fix security vulnerability: An assertion failure was found in the way the libyaml library parsed wrapped strings. An attacker able to load specially crafted YAML input into an application using libyaml could cause the application to crash (CVE-2014-9130). The perl-YAML-LibYAML package is also affected, as it was derived from the same code. Both have been patched to fix this issue.
References: https://advisories.mageia.org/MGASA-2014-0508.html, https://bugs.mageia.org/show_bug.cgi?id=14689, https://bugzilla.redhat.com/show_bug.cgi?id=1169369
Affected packages
Package
Name: yaml
Purl: pkg:rpm/mageia/yaml?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
