ALAS-2015-482

Related Vulnerabilities: CVE-2014-9130  

An assertion failure was found in the way the libyaml library parsed wrapped strings. An attacker able to load specially crafted YAML input into an application using libyaml could cause the application to crash.

ALAS-2015-482


Amazon Linux AMI Security Advisory: ALAS-2015-482
Advisory Release Date: 2015-02-11 19:39 Pacific
Advisory Updated Date: 2015-02-11 19:54 Pacific
Severity: Medium
References: CVE-2014-9130 

Issue Overview:

An assertion failure was found in the way the libyaml library parsed wrapped strings. An attacker able to load specially crafted YAML input into an application using libyaml could cause the application to crash.


Affected Packages:

perl-YAML-LibYAML


Issue Correction:
Run yum update perl-YAML-LibYAML to update your system.

New Packages:
i686:
    perl-YAML-LibYAML-0.59-1.16.amzn1.i686
    perl-YAML-LibYAML-debuginfo-0.59-1.16.amzn1.i686

src:
    perl-YAML-LibYAML-0.59-1.16.amzn1.src

x86_64:
    perl-YAML-LibYAML-debuginfo-0.59-1.16.amzn1.x86_64
    perl-YAML-LibYAML-0.59-1.16.amzn1.x86_64