drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Denial of Service in PyYAML (Aktualisierung)
Name: |
Denial of Service in PyYAML (Aktualisierung) |
|
ID: |
USN-2461-3 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 14.10 |
|
Datum: |
Di, 13. Januar 2015, 07:38 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9130 |
|
Applikationen: |
PyYAML |
|
Update von: |
Denial of Service in LibYAML |
|
Originalnachricht |
--===============2670984928627193928== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="3Gf/FFewwPeBMqCJ" Content-Disposition: inline
--3Gf/FFewwPeBMqCJ Content-Type: text/plain; charset=utf-8 Content-Disposition: inlin Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-2461-3 January 12, 2015
pyyaml vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS
Summary:
Applications using PyYAML could be made to crash if they received specially crafted input.
Software Description: - pyyaml: YAML parser and emitter for Python
Details:
StanisÅaw Pitucha and Jonathan Gray discovered that PyYAML did not properly handle wrapped strings. An attacker could create specially crafted YAML data to trigger an assert, causing a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 14.10: python-yaml 3.11-1ubuntu0.1 python3-yaml 3.11-1ubuntu0.1
Ubuntu 14.04 LTS: python-yaml 3.10-4ubuntu0.1 python3-yaml 3.10-4ubuntu0.1
Ubuntu 12.04 LTS: python-yaml 3.10-2ubuntu0.1 python3-yaml 3.10-2ubuntu0.1
After a standard system update you need to restart applications using PyYAML to make all the necessary changes.
References: http://www.ubuntu.com/usn/usn-2461-3 CVE-2014-9130
Package Information: https://launchpad.net/ubuntu/+source/pyyaml/3.11-1ubuntu0.1 https://launchpad.net/ubuntu/+source/pyyaml/3.10-4ubuntu0.1 https://launchpad.net/ubuntu/+source/pyyaml/3.10-2ubuntu0.1
--3Gf/FFewwPeBMqCJ Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1
iQIcBAEBCgAGBQJUtEpwAAoJEC8Jno0AXoH0t6MP/A/XaaORDAktO+van79m3IGU xKwcRaXezAN/ePt0b1fN2biDsuK+YDGTxn7DkL6d7udDmJ/zeEVyjTr8WFLpSU6N OFwSI+dQk58AX7oE5vdu1A+QcCeNhO7DAVYdYlLTxQVJnr4aOno20DGwGyy78fFa vksbtnRll1vl5Ybpcihy2V0B2l9m5UILGmdmCxX7vMnFiSVOErkkJdFPkrhigvIt vXgHZm5mkIn77MAYdBdW5P099F51ilrU65CdL3ZwKNtgaXvZJcI9aqz4H0T6SpPf EtOdrSWpVG3s0ZQf3DgumDmU5EaOzRjQOMJxTQFG4+pIN3cNeXT4f14vGIqqrbXV brXg0Z22qtCK/O6XJhtaLBuTj+2yzHFFYxkm/6rkCKDoXp/wv/mnvr+AK3QbCnqd JPnXXvy0f3CLr/xF6JmmGJW4MXCm6tEP16CSqjoSFXjRHxo0jWZyeHzRyD6Ua/8E afqctTGA31eRXt3ARST1+bwRsdRj7CKJDRrXVZOyEw4WxkjyGDYcJtYi4Y6DaJBU pRXiItBOrBoq2uxjBY1X5De6s9S7Bj39SLEcJu3rWLXufYVpDzFhRXCU4AKaEpUy xweHpPHlrLo8txum6nEnwLkJVk6iiz+Xo5jegzk1CrbbfxlaA2gUSnFIgr1tcE4f kd9JdyG8tcs0d4mv0qr7 =+Sca -----END PGP SIGNATURE-----
--3Gf/FFewwPeBMqCJ--
--===============2670984928627193928== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============2670984928627193928==--
|
|
|
|