Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Mageia 6: MGASA-2019-0125 Critical: Python-YAML Arbitrary Code Execution

mageia
Calendar Grey April 5, 2019
Dist Mageia Esm H88
A new security patch for python-yaml addresses a critical vulnerability that may enable unauthorized code execution. Detailed information is included in this advisory
It was found that using yaml.load() API on untrusted input could lead to arbitrary code execution (CVE-2017-18342)

Summary

It was found that using yaml.load() API on untrusted input could lead to arbitrary code execution (CVE-2017-18342).

References

- https://bugs.mageia.org/show_bug.cgi?id=23242

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/JEX7IPV5P2QJITAMA5Z63GQCZA5I6NVZ/

- https://www.cve.org/CVERecord?id=CVE-2017-18342

Resolution

SRPMS

- 6/core/python-yaml-5.1-1.1.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 05 Apr 2019
URL: https://advisories.mageia.org/MGASA-2019-0125.html
Type: security
CVE: CVE-2017-18342

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here