Denial of Service in PyYAML (Aktualisierung)
ID: | USN-2461-3 |
Distribution: | Ubuntu |
Plattformen: | Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 14.10 |
Datum: | Di, 13. Januar 2015, 07:38 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9130 |
Applikationen: | PyYAML |
Update von: | Denial of Service in LibYAML |
Originalnachricht |
|
--===============2670984928627193928== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="3Gf/FFewwPeBMqCJ" Content-Disposition: inline --3Gf/FFewwPeBMqCJ Content-Type: text/plain; charset=utf-8 Content-Disposition: inlin Content-Transfer-Encoding: quoted-printable ========================================================================== Ubuntu Security Notice USN-2461-3 January 12, 2015 pyyaml vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Applications using PyYAML could be made to crash if they received specially crafted input. Software Description: - pyyaml: YAML parser and emitter for Python Details: StanisÅaw Pitucha and Jonathan Gray discovered that PyYAML did not properly handle wrapped strings. An attacker could create specially crafted YAML data to trigger an assert, causing a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: python-yaml 3.11-1ubuntu0.1 python3-yaml 3.11-1ubuntu0.1 Ubuntu 14.04 LTS: python-yaml 3.10-4ubuntu0.1 python3-yaml 3.10-4ubuntu0.1 Ubuntu 12.04 LTS: python-yaml 3.10-2ubuntu0.1 python3-yaml 3.10-2ubuntu0.1 After a standard system update you need to restart applications using PyYAML to make all the necessary changes. References: http://www.ubuntu.com/usn/usn-2461-3 CVE-2014-9130 Package Information: https://launchpad.net/ubuntu/+source/pyyaml/3.11-1ubuntu0.1 https://launchpad.net/ubuntu/+source/pyyaml/3.10-4ubuntu0.1 https://launchpad.net/ubuntu/+source/pyyaml/3.10-2ubuntu0.1 --3Gf/FFewwPeBMqCJ Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJUtEpwAAoJEC8Jno0AXoH0t6MP/A/XaaORDAktO+van79m3IGU xKwcRaXezAN/ePt0b1fN2biDsuK+YDGTxn7DkL6d7udDmJ/zeEVyjTr8WFLpSU6N OFwSI+dQk58AX7oE5vdu1A+QcCeNhO7DAVYdYlLTxQVJnr4aOno20DGwGyy78fFa vksbtnRll1vl5Ybpcihy2V0B2l9m5UILGmdmCxX7vMnFiSVOErkkJdFPkrhigvIt vXgHZm5mkIn77MAYdBdW5P099F51ilrU65CdL3ZwKNtgaXvZJcI9aqz4H0T6SpPf EtOdrSWpVG3s0ZQf3DgumDmU5EaOzRjQOMJxTQFG4+pIN3cNeXT4f14vGIqqrbXV brXg0Z22qtCK/O6XJhtaLBuTj+2yzHFFYxkm/6rkCKDoXp/wv/mnvr+AK3QbCnqd JPnXXvy0f3CLr/xF6JmmGJW4MXCm6tEP16CSqjoSFXjRHxo0jWZyeHzRyD6Ua/8E afqctTGA31eRXt3ARST1+bwRsdRj7CKJDRrXVZOyEw4WxkjyGDYcJtYi4Y6DaJBU pRXiItBOrBoq2uxjBY1X5De6s9S7Bj39SLEcJu3rWLXufYVpDzFhRXCU4AKaEpUy xweHpPHlrLo8txum6nEnwLkJVk6iiz+Xo5jegzk1CrbbfxlaA2gUSnFIgr1tcE4f kd9JdyG8tcs0d4mv0qr7 =+Sca -----END PGP SIGNATURE----- --3Gf/FFewwPeBMqCJ-- --===============2670984928627193928== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce --===============2670984928627193928==-- |