2014 m. gruodžio 15 d., pirmadienis

[SECURITY] [DSA 3102-1] libyaml security update

Debian Security Advisory DSA-3102-1                   security@debian.org
http://www.debian.org/security/                      Salvatore Bonaccorso
December 13, 2014                      http://www.debian.org/security/faq
- ------------------------------------------------------------
-------------

Package        : libyaml
CVE ID         : CVE-2014-9130
Debian Bug     : 771366

Jonathan Gray and Stanislaw Pitucha found an assertion failure in the
way wrapped strings are parsed in LibYAML, a fast YAML 1.1 parser and
emitter library. An attacker able to load specially crafted YAML input
into an application using libyaml could cause the application to crash.

For the stable distribution (wheezy), this problem has been fixed in
version 0.1.4-2+deb7u5.

For the upcoming stable distribution (jessie), this problem has been
fixed in version 0.1.6-3.

For the unstable distribution (sid), this problem has been fixed in
version 0.1.6-3.

We recommend that you upgrade your libyaml packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

Komentarų nėra:

Rašyti komentarą