SUSE-SU-2022:3397-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3397-1
SUSE-SU-2022:3397-1
Summary: Security update for snakeyaml
Details: This update for snakeyaml fixes the following issues: - CVE-2022-38750: Fixed uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject (bsc#1203158). - CVE-2022-38749: Fixed StackOverflowError for many open unmatched brackets (bsc#1203149). - CVE-2022-38752: Fixed uncaught exception in java.base/java.util.ArrayList.hashCode (bsc#1203154). - CVE-2022-38751: Fixed unrestricted data matched with Regular Expressions (bsc#1203153). - CVE-2022-25857: Fixed denial of service vulnerability due missing to nested depth limitation for collections (bsc#1202932).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223397-1/, https://bugzilla.suse.com/1202932, https://bugzilla.suse.com/1203149, https://bugzilla.suse.com/1203153, https://bugzilla.suse.com/1203154, https://bugzilla.suse.com/1203158, https://www.suse.com/security/cve/CVE-2020-13936, https://www.suse.com/security/cve/CVE-2022-25857, https://www.suse.com/security/cve/CVE-2022-38749, https://www.suse.com/security/cve/CVE-2022-38750, https://www.suse.com/security/cve/CVE-2022-38751, https://www.suse.com/security/cve/CVE-2022-38752
Affected packages
Package
Name: snakeyaml
Purl: pkg:rpm/suse/snakeyaml&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
