Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora 20: 2015-4477 Critical: PyYAML Security Fix for CVE-2014-9130

fedora
Calendar Grey April 5, 2015
Dist Fedora Esm H88
Critical update available for PyYAML in Fedora 20 to address CVE-2014-9130. Reinforce your system's security now.
Security fix for CVE-2014-9130

Summary

YAML is a data serialization format designed for human readability and

interaction with scripting languages. PyYAML is a YAML parser and

emitter for Python.

PyYAML features a complete YAML 1.1 parser, Unicode support, pickle

support, capable extension API, and sensible error messages. PyYAML

supports standard YAML tags and provides Python-specific tags that

allow to represent an arbitrary Python object.

PyYAML is applicable for a broad range of tasks from complex

configuration files to object serialization and persistance.

Update Information:

Security fix for CVE-2014-9130

Change Log

* Mon Mar 23 2015 John Eckersberg - 3.10-11 - Add patch for CVE-2014-9130 (bug 1204829) * Mon Sep 15 2014 Jakub ÄŒajka - 3.10-10 - fixed typecast issues using debian patch(int->size_t)(BZ#1140189) - spec file cleanup

References


[ 1 ] Bug #1204829 - PyYAML: assert failure when processing wrapped strings https://bugzilla.redhat.com/show_bug.cgi?id=1204829

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update PyYAML' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: PyYAML
Product: Fedora 20
Version: 3.10
Release: 11.fc20
Summary: YAML parser and emitter for Python

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here