Denial of Service in libyaml-libyaml-perl
ID: | USN-2461-2 |
Distribution: | Ubuntu |
Plattformen: | Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 14.10 |
Datum: | Di, 13. Januar 2015, 07:38 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9130 |
Applikationen: | libyaml-libyaml-perl |
Originalnachricht |
|
--===============5769041211352436452== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="4jXrM3lyYWu4nBt5" Content-Disposition: inline --4jXrM3lyYWu4nBt5 Content-Type: text/plain; charset=utf-8 Content-Disposition: inlin Content-Transfer-Encoding: quoted-printable ========================================================================== Ubuntu Security Notice USN-2461-2 January 12, 2015 libyaml-libyaml-perl vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Applications using libyaml-libyaml-perl could be made to crash if they received specially crafted input. Software Description: - libyaml-libyaml-perl: Perl interface to libyaml, a YAML implementation Details: StanisÅaw Pitucha and Jonathan Gray discovered that libyaml-libyaml-perl did not properly handle wrapped strings. An attacker could create specially crafted YAML data to trigger an assert, causing a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: libyaml-libyaml-perl 0.41-5ubuntu0.14.10.1 Ubuntu 14.04 LTS: libyaml-libyaml-perl 0.41-5ubuntu0.14.04.1 Ubuntu 12.04 LTS: libyaml-libyaml-perl 0.38-2ubuntu0.2 After a standard system update you need to restart applications using libyaml-libyaml-perl to make all the necessary changes. References: http://www.ubuntu.com/usn/usn-2461-2 CVE-2014-9130 Package Information: https://launchpad.net/ubuntu/+source/libyaml-libyaml-perl/0.41-5ubuntu0.14.10.1 https://launchpad.net/ubuntu/+source/libyaml-libyaml-perl/0.41-5ubuntu0.14.04.1 https://launchpad.net/ubuntu/+source/libyaml-libyaml-perl/0.38-2ubuntu0.2 --4jXrM3lyYWu4nBt5 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJUtEpkAAoJEC8Jno0AXoH0/rIQAKcNt39Azn3ZFHN9CukDrS7D I9L7am70Xi1s2wAyoiWcCxPnzaTCdXyLTjiODSFJ1Y0gM7DioidepDNLVzueWNbK B0odHnGzQ0K5RnNDYP7YTjgkBiaKP68jfRO4sM+wFPAXcU2uie0kKE4h3fhA0F/x KlfI2vxPV7vFW+N/FBZEzvn81hiEbxWWCEvZj7rEQLoJwbo85amnNUX7Pbv57IQM Zo3bx1tthMwZm2Fkjny7SAu7Qmf80iLKo2ibKwB93qTjV1iwN2DlO/oREClCEJNG Cr2JXinVUUNvhm+sGfMupOGj+KkMwadQEpzJeqW9KxnSrW9cCP1ED2kl+ujLbK5P w0Yy+BGPpFE6PzwPgGOMFEx44PMKwQwyM2QiCSL2gHcZR0aBWs/1t693H1QVgM3B 5413eqZRhtQgYjKBwjGj2VWR8D/YrICSGWKPrQORhyp2IaE3tZZ6wivXqGXlMWGo WzKXC3QZS/9AfAbocWHpTsqGqEo7QF5PD+vwXT6fcmzLubHqhWKPc3lLVY9T5OsX Nywl0DFVEfefAt9pYgFM7rNjhxiS8p1UCs8SWs5kQ65DnJb5R/DSqy0NKPL+PYYW Y6/DDY3lHkLcrNPkgrLWVGDjvVzh7vMWY9uqMyG4THGUyUHeaRY8/fd7V6qM5MnE iDYDOfsF7cHGTW/U09C9 =zVqo -----END PGP SIGNATURE----- --4jXrM3lyYWu4nBt5-- --===============5769041211352436452== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce --===============5769041211352436452==-- |