Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2015.0003 pyyaml security update 5 January 2015 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: pyyaml Publisher: Debian Operating System: Debian GNU/Linux 7 UNIX variants (UNIX, Linux, OSX) Windows Impact/Access: Denial of Service -- Remote/Unauthenticated Resolution: Patch/Upgrade CVE Names: CVE-2014-9130 Reference: ESB-2014.2393 Original Bulletin: http://www.debian.org/security/2014/dsa-3115 - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - ------------------------------------------------------------------------- Debian Security Advisory DSA-3115-1 security@debian.org http://www.debian.org/security/ Moritz Muehlenhoff December 29, 2014 http://www.debian.org/security/faq - - ------------------------------------------------------------------------- Package : pyyaml CVE ID : CVE-2014-9130 Debian Bug : 772815 Jonathan Gray and Stanislaw Pitucha found an assertion failure in the way wrapped strings are parsed in Python-YAML, a YAML parser and emitter for Python. An attacker able to load specially crafted YAML input into an application using python-yaml could cause the application to crash. For the stable distribution (wheezy), this problem has been fixed in version 3.10-4+deb7u1. For the upcoming stable distribution (jessie), this problem has been fixed in version 3.11-2. For the unstable distribution (sid), this problem has been fixed in version 3.11-2. We recommend that you upgrade your pyyaml packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org - -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBAgAGBQJUochoAAoJEBDCk7bDfE42uksP/iffDvE9L3Wm1DcVVgtWmzgK Piq6PdO3ztbcSW6av53E5MgVDixQgmyqPluWQOU0GGdcbWtpNBbWw7loyLjeu692 d0pVvxtmDQXWaXMcYTMxPnL6mub6HtIUSxeaymiOSeY7kAaV4HOntPQrivMrPM0n hlmtQsu6whSXP3BqaXffL9mGeIVfmknGnMOdkJq41nrSJIkjN/BN+jBca8BHhizA J0ntxYu0CZyLUTKyKWhTTmgxRPWTyyr/+s3a7Xrjn6+Wkj8SF7XP+2NLLLDshY/R tBSfuRmk+tx/249PTXhLEvQvS7mR+FouMfYHsAJjPtIqmxXk6BkRxI3W4I5felP+ ntAGX22o51SAIrm4fQDKlJW5wDowRu1iP7K8uQx2xWhGLo7w3QIreYU1J/ny6Xpe Ms57exgDHnYrmJs68bdAKRHTyZScr+4s/DapW/awBBLap3uhU3qjMfnyj4XDhC+u 5gkIcok8uBxvkS4Sh1zkykNJL8efEY0CeyzNiAMwkSG3qfC9EgSQFh7M8bNg6Iie 8gnGy4WpqecY2lpE5ZmAThlsFmoWhIhM6AVRqKqcSYI/2P4qs/mhxTeTqphh7+xe Fz3r2CNAQtF0T2wU66+BVFg+6IYUkyjHg/GdtGAfvR7UVdNN8fwlao8U+bTaEfD+ EQoTq8Ql4+hnEJR+Sk1r =Usft - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: http://www.auscert.org.au/render.html?cid=1980 =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBVKnRbhLndAQH1ShLAQKsQw//eiVeoqzyHL/DATKo8OEXD58V2i7ZFx2k b4b3rbEyI2AEeTN4HzsO3OPCTin2ZvHEUaFm4dS7P8eN5Pq5Y+7JUL0Vzrmay+Qt agKBIx4AeO2ZSWMeZT9J9fXn0NAF/PjAQ5wWQL1U7Yz6kd3IN7P0jp6VdHgAFLBT uneH61X0ifDinukN7SB2W4JWWjn+FDpxFX9rhXZnO/q5TTLCt0T+T59zY+dgbgOQ RutRZYasHp260D/66iutYV01oBMDWtsqjzAZfTdcH2c83aKdFK1GR6+iaO3nP9tT r3njtIkItu8UP4as6MppAAUw/Fa+Bsx6OHQ5FoNoC4Ji9/Vq/C/nYjLMaiudzUo/ wSW78WwkNbkCkQOrh7PZy6V1oh/9ovcQTeOecU8LOh6uhpM1H4vr1mKaXcC2kv9p 6YDhz4DTBLjP454ka2yUQ9qKX+OAB70oKDUZHSXncaOtEhlN5sgIhgUftGb9i7rj mIFYxx6shpnZhVeVkMJRZhbVXWMTIeMm7FLnc5a1FzDk1bd/nDyXt8gKflktv+BM XLNElHSJHiJC3wAi9TUAJ+l8ZBopjg7r8T1m6fZR+WEu17nd61bbkIs3OmWZ0IzV sADh4Dj1+25ZH9+4fpdpzFNMZfmowEnAtBlTZFJZjYYBWydh90AwBCv6RBcJCxhI QMNWgPcSHD8= =9xQz -----END PGP SIGNATURE-----