MGASA-2015-0004
Dashboard / Vulnerabilities / MGASA-2015-0004
Summary: Updated python-yaml packages fix security vulnerability
Details: Updated python-yaml packages fix security vulnerability: Jonathan Gray and Stanislaw Pitucha found an assertion failure in the way wrapped strings are parsed in Python-YAML, a YAML parser and emitter for Python. An attacker able to load specially crafted YAML input into an application using python-yaml could cause the application to crash. This issue is similar to CVE-2014-9130, but the assertion was independently implemented in Python-YAML.
References: https://advisories.mageia.org/MGASA-2015-0004.html, https://bugs.mageia.org/show_bug.cgi?id=14917, http://advisories.mageia.org/MGASA-2014-0508.html, https://www.debian.org/security/2014/dsa-3115
Affected packages
Package
Name: python-yaml
Purl: pkg:rpm/mageia/python-yaml?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
