Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
PyYAML could be made to run programs if it opened a specially crafted YAML file.. =========================================================================Ubuntu Security Notice USN-4940-1 May 10, 2021 pyyaml vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS Summary: PyYAML could be made to run programs if it opened a specially crafted YAML file. Software Description: - pyyaml: YAML parser and emitter for Python Details: It was discovered that PyYAML incorrectly handled untrusted YAML files with the FullLoader loader. A remote attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: python3-yaml 5.3.1-2ubuntu0.1 Ubuntu 20.04 LTS: python-yaml 5.3.1-1ubuntu0.1 python3-yaml 5.3.1-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4940-1 CVE-2020-14343 Package Information: https://launchpad.net/ubuntu/+source/pyyaml/5.3.1-2ubuntu0.1 https://launchpad.net/ubuntu/+source/pyyaml/5.3.1-1ubuntu0.1 . To secure your Ubuntu system against PyYAML vulnerabilities, follow these update steps carefully and strengthen your environment against remote code execution risks. Remote Code Execution, PyYAML Patch, Ubuntu 20.04 LTS, Security Update. . Severity: Critical. LinuxSecurity.com Team
Applications using PyYAML could be made to crash if they received specially crafted input.. =========================================================================Ubuntu Security Notice USN-2461-3 January 12, 2015 pyyaml vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Applications using PyYAML could be made to crash if they received specially crafted input. Software Description: - pyyaml: YAML parser and emitter for Python Details: Stanisław Pitucha and Jonathan Gray discovered that PyYAML did not properly handle wrapped strings. An attacker could create specially crafted YAML data to trigger an assert, causing a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: python-yaml 3.11-1ubuntu0.1 python3-yaml 3.11-1ubuntu0.1 Ubuntu 14.04 LTS: python-yaml 3.10-4ubuntu0.1 python3-yaml 3.10-4ubuntu0.1 Ubuntu 12.04 LTS: python-yaml 3.10-2ubuntu0.1 python3-yaml 3.10-2ubuntu0.1 After a standard system update you need to restart applications using PyYAML to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2461-3 CVE-2014-9130 Package Information: https://launchpad.net/ubuntu/+source/pyyaml/3.11-1ubuntu0.1 https://launchpad.net/ubuntu/+source/pyyaml/3.10-4ubuntu0.1 https://launchpad.net/ubuntu/+source/pyyaml/3.10-2ubuntu0.1 . Ubuntu Security Alert USN-2461-3 explores a PyYAML flaw affecting users, delivering critical patches.. Ubuntu Vulnerability, PyYAML Security, Denial Of Service, Software Update. . Severity: Critical. LinuxSecurity.com Team
Jonathan Gray and Stanislaw Pitucha found an assertion failure in the way wrapped strings are parsed in Python-YAML, a YAML parser and emitter for Python. An attacker able to load specially crafted YAML input into an application using python-yaml could cause the application to crash. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3115-1
Get the latest Linux and open source security news straight to your inbox.