Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Ubuntu 22.10: USN-5944-1 critical: SnakeYAML Denial of Service

ubuntu
Calendar Grey March 10, 2023
Scroller Ubuntu
A range of security flaws addressed in SnakeYAML could impact various versions of Ubuntu. Make sure your system is current to avert potential problems.
Several security issues were fixed in SnakeYAML.

Summary

Several security issues were fixed in SnakeYAML.

Software Description:

- snakeyaml: YAML parser and emitter for the Java programming language

Details:

It was discovered that SnakeYAML did not limit the maximal nested depth

for collections when parsing YAML data. If a user or automated system were

tricked into opening a specially crafted YAML file, an attacker could

possibly use this issue to cause applications using SnakeYAML to crash,

resulting in a denial of service. (CVE-2022-25857, CVE-2022-38749,

CVE-2022-38750)

It was discovered that SnakeYAML did not limit the maximal data matched

with regular expressions when parsing YAML data. If a user or automated

system were tricked into opening a specially crafted YAML file, an

attacker could possibly use this issue to cause applications using

SnakeYAML to crash, resulting in a denial of service. (CVE-2022-38751)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.10:
   libyaml-snake-java              1.29-1ubuntu0.22.10.1

Ubuntu 22.04 LTS:
   libyaml-snake-java              1.29-1ubuntu0.22.04.1

Ubuntu 20.04 LTS:
   libyaml-snake-java              1.25+ds-2ubuntu0.1

Ubuntu 18.04 LTS:
   libyaml-snake-java              1.23-1+deb10u1build0.18.04.1

Ubuntu 16.04 ESM:
   libyaml-snake-java              1.12-2ubuntu0.16.04.1~esm1

Ubuntu 14.04 ESM:
   libyaml-snake-java              1.12-2ubuntu0.14.04.1~esm1

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-5944-1

  CVE-2022-25857, CVE-2022-38749, CVE-2022-38750, CVE-2022-38751

Severity
critical
Lowest
Low
Medium
High
Critical

March 10, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.