![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.1.13.2014.111.01 |
Category: | Slackware Local Security Checks |
Title: | Slackware: Security Advisory (SSA:2014-111-01) |
Summary: | The remote host is missing an update for the 'libyaml' package(s) announced via the SSA:2014-111-01 advisory. |
Description: | Summary: The remote host is missing an update for the 'libyaml' package(s) announced via the SSA:2014-111-01 advisory. Vulnerability Insight: New libyaml packages are available for Slackware 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +--------------------------+ patches/packages/libyaml-0.1.6-i486-1_slack14.1.txz: Upgraded. This update fixes a heap overflow in URI escape parsing of YAML in Ruby, where a specially crafted string could cause a heap overflow leading to arbitrary code execution. For more information, see: [links moved to references] (* Security fix *) +--------------------------+ Affected Software/OS: 'libyaml' package(s) on Slackware 13.1, Slackware 13.37, Slackware 14.0, Slackware 14.1, Slackware current. Solution: Please install the updated package(s). CVSS Score: 6.8 CVSS Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2014-2525 BugTraq ID: 66478 http://www.securityfocus.com/bid/66478 Debian Security Information: DSA-2884 (Google Search) http://www.debian.org/security/2014/dsa-2884 Debian Security Information: DSA-2885 (Google Search) http://www.debian.org/security/2014/dsa-2885 http://www.mandriva.com/security/advisories?name=MDVSA-2015:060 http://www.ocert.org/advisories/ocert-2014-003.html RedHat Security Advisories: RHSA-2014:0353 http://rhn.redhat.com/errata/RHSA-2014-0353.html RedHat Security Advisories: RHSA-2014:0354 http://rhn.redhat.com/errata/RHSA-2014-0354.html RedHat Security Advisories: RHSA-2014:0355 http://rhn.redhat.com/errata/RHSA-2014-0355.html http://secunia.com/advisories/57836 http://secunia.com/advisories/57966 http://secunia.com/advisories/57968 SuSE Security Announcement: openSUSE-SU-2014:0500 (Google Search) http://lists.opensuse.org/opensuse-updates/2014-04/msg00022.html SuSE Security Announcement: openSUSE-SU-2015:0319 (Google Search) http://lists.opensuse.org/opensuse-updates/2015-02/msg00078.html SuSE Security Announcement: openSUSE-SU-2016:1067 (Google Search) http://lists.opensuse.org/opensuse-updates/2016-04/msg00050.html http://www.ubuntu.com/usn/USN-2160-1 |
Copyright | Copyright (C) 2022 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |