ALAS-2015-481

Related Vulnerabilities: CVE-2014-9130  

An assertion failure was found in the way the libyaml library parsed wrapped strings. An attacker able to load specially crafted YAML input into an application using libyaml could cause the application to crash. (CVE-2014-9130)

ALAS-2015-481


Amazon Linux AMI Security Advisory: ALAS-2015-481
Advisory Release Date: 2015-02-11 19:38 Pacific
Advisory Updated Date: 2015-02-11 19:50 Pacific
Severity: Medium

Issue Overview:

An assertion failure was found in the way the libyaml library parsed wrapped strings. An attacker able to load specially crafted YAML input into an application using libyaml could cause the application to crash. (CVE-2014-9130)


Affected Packages:

libyaml


Issue Correction:
Run yum update libyaml to update your system.

New Packages:
i686:
    libyaml-devel-0.1.6-6.7.amzn1.i686
    libyaml-debuginfo-0.1.6-6.7.amzn1.i686
    libyaml-0.1.6-6.7.amzn1.i686

src:
    libyaml-0.1.6-6.7.amzn1.src

x86_64:
    libyaml-0.1.6-6.7.amzn1.x86_64
    libyaml-devel-0.1.6-6.7.amzn1.x86_64
    libyaml-debuginfo-0.1.6-6.7.amzn1.x86_64