CVE-2014-9130
Publication date 8 December 2014
Last updated 24 July 2024
Ubuntu priority
scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping.
Status
Package | Ubuntu Release | Status |
---|---|---|
libyaml | ||
14.04 LTS trusty |
Fixed 0.1.4-3ubuntu3.1
|
|
libyaml-libyaml-perl | ||
14.04 LTS trusty |
Fixed 0.41-5ubuntu0.14.04.1
|
|
pyyaml | ||
14.04 LTS trusty |
Fixed 3.10-4ubuntu0.1
|
|
Notes
seth-arnold
pyyaml may receive its own CVE
mdeslaur
perl PoC: http://www.openwall.com/lists/oss-security/2014/11/28/6
sbeattie
ruby1.9+ uses libyaml-0-2, so it's fixed when libyaml is fixed
Patch details
Package | Patch details |
---|---|
libyaml | |
pyyaml |
References
Related Ubuntu Security Notices (USN)
- USN-2461-1
- LibYAML vulnerability
- 12 January 2015
- USN-2461-3
- PyYAML vulnerability
- 12 January 2015
- USN-2461-2
- libyaml-libyaml-perl vulnerability
- 12 January 2015