USN-2461-2: libyaml-libyaml-perl vulnerability

Ubuntu Security Notice USN-2461-2

12th January, 2015

libyaml-libyaml-perl vulnerability

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 14.10
  • Ubuntu 14.04 LTS
  • Ubuntu 12.04 LTS

Summary

Applications using libyaml-libyaml-perl could be made to crash if
they received specially crafted input.

Software description

  • libyaml-libyaml-perl
    – Perl interface to libyaml, a YAML implementation

Details

Stanisław Pitucha and Jonathan Gray discovered that
libyaml-libyaml-perl did not properly handle wrapped strings. An
attacker could create specially crafted YAML data to trigger an assert,
causing a denial of service.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 14.10:
libyaml-libyaml-perl

0.41-5ubuntu0.14.10.1
Ubuntu 14.04 LTS:
libyaml-libyaml-perl

0.41-5ubuntu0.14.04.1
Ubuntu 12.04 LTS:
libyaml-libyaml-perl

0.38-2ubuntu0.2

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to restart applications using
libyaml-libyaml-perl to make all the necessary changes.

References

CVE-2014-9130

MS14-080 CVE-2014-6365 Technical Details Without "Nonsense"

Posted by Diéyǔ on Jan 13

Origin:
Visit https://technet.microsoft.com/library/security/ms14-080
Go to “Acknowledgments” part and search for “CVE-2014-6365”
It says “Dieyu” – that’s me.

Technical Details:
“Internet Explorer XSS Filter Bypass Vulnerability” is done by…
1. Inject “a href” link into target page.
(Not script, allowed by filter)
2. User clicks this injected link.
(Clickjacking etc)
3. URL of this…

Re: McAfee ePolicy Orchestrator Authenticated XXE and Credential Exposure

Posted by Tim on Jan 13

Hi Brandon,

Yes, you should. For those out there who don’t routinely find
vulnerabilities, it is hard for them to understand that these issues
aren’t hard to find if you know what you’re looking for. Quite a few
bugs I’ve found in the past have been found by others independently
and published before I got around to it. It happens a LOT more than
people think.

Also, I think companies that sell security software should be…

[Corrected] Stored XSS Vulnerability in F5 BIG-IP Application Security Manager

Posted by Peter Lapp on Jan 13

Edit: Corrected the date in the timeline from 01/12/14 to 01/12/15.

Details
=======

Product: F5 BIG-IP Application Security Manager (ASM)
Vulnerability: Cross Site Scripting
Author: Peter Lapp, lappsec () gmail com
CVE: None assigned
Vulnerable Versions: Confirmed 11.4.0, 11.4.1. Likely 11.4.x-11.5.x.
Fixed Version: 11.6

Summary
=======

The F5 ASM is a web application firewall designed to protect web
applications from attacks. It allows for a…