Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 12.04 LTS: 2161-1 Critical: libyaml-libyaml-perl DoS Risk

ubuntu
Calendar Grey April 3, 2014
Scroller Ubuntu
Recent findings reveal vulnerabilities in the libyaml-libyaml-perl package, mainly linked to a Denial of Service (DoS) threat and arbitrary code execution risks
libyaml-libyaml-perl could be made to crash or run programs if it opened a specially crafted YAML file.

Summary

libyaml-libyaml-perl could be made to crash or run programs if it opened a

specially crafted YAML file.

Software Description:

- libyaml-libyaml-perl: Perl interface to libyaml, a YAML implementation

Details:

Florian Weimer discovered that libyaml-libyaml-perl incorrectly handled

certain large YAML documents. An attacker could use this issue to cause

libyaml-libyaml-perl to crash, resulting in a denial of service, or

possibly execute arbitrary code. (CVE-2013-6393)

Ivan Fratric discovered that libyaml-libyaml-perl incorrectly handled

certain malformed YAML documents. An attacker could use this issue to cause

libyaml-libyaml-perl to crash, resulting in a denial of service, or

possibly execute arbitrary code. (CVE-2014-2525)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  libyaml-libyaml-perl            0.38-3ubuntu0.13.10.1

Ubuntu 12.10:
  libyaml-libyaml-perl            0.38-3ubuntu0.12.10.1

Ubuntu 12.04 LTS:
  libyaml-libyaml-perl            0.38-2ubuntu0.1

After a standard system update you need to restart applications using
libyaml-libyaml-perl to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2161-1

CVE-2013-6393, CVE-2014-2525

Severity
critical
Lowest
Low
Medium
High
Critical

April 03, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.