Boletines de Vulnerabilidades |
DSA-2885 libyaml-libyaml-perl - security update |
|
| Software afectado | Debian |
|
Ivan Fratric of the Google Security Team discovered a heap-based bufferoverflow vulnerability in LibYAML, a fast YAML 1.1 parser and emitterlibrary. A remote attacker could provide a specially-crafted YAMLdocument that, when parsed by an application using libyaml, would causethe application to crash or, potentially, execute arbitrary code withthe privileges of the user running the application. More info: http://www.debian.org/security/2014/dsa-2885 |
|














