Bug 836924 - CVE-2012-1152 perl-YAML-LibYAML: Multiple format string flaws by reporting errors during YAML document load [epel-6]
Summary: CVE-2012-1152 perl-YAML-LibYAML: Multiple format string flaws by reporting er...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: perl-YAML-LibYAML
Version: el6
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Paul Howarth
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: CVE-2012-1152
TreeView+ depends on / blocked
 
Reported: 2012-07-02 07:54 UTC by Huzaifa S. Sidhpurwala
Modified: 2012-07-21 12:35 UTC (History)
2 users (show)

Fixed In Version: perl-YAML-LibYAML-0.38-3.el6
Clone Of:
Environment:
Last Closed: 2012-07-21 12:35:27 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Huzaifa S. Sidhpurwala 2012-07-02 07:54:35 UTC
This is an automatically created tracking bug!  It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.

For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.

For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs

When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs).  Please mention the CVE IDs being fixed
in the RPM changelog when available.

Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=801738

epel-6 tracking bug for perl-YAML-LibYAML: see blocks bug list for full details of the security issue(s).

[bug automatically created by: add-tracking-bugs]

Comment 1 Paul Howarth 2012-07-02 09:50:07 UTC
I have a fix for this (basically updating the package in EPEL-6 to the same as was built for Fedora in April), which I could build if tremble is OK with that.

Comment 2 Huzaifa S. Sidhpurwala 2012-07-05 04:00:13 UTC
(In reply to comment #1)
> I have a fix for this (basically updating the package in EPEL-6 to the same
> as was built for Fedora in April), which I could build if tremble is OK with
> that.

Ok you could backport the patch, the patch looks pretty simple to me :)

Comment 3 Paul Howarth 2012-07-05 08:16:10 UTC
(In reply to comment #2)
> (In reply to comment #1)
> > I have a fix for this (basically updating the package in EPEL-6 to the same
> > as was built for Fedora in April), which I could build if tremble is OK with
> > that.
> 
> Ok you could backport the patch, the patch looks pretty simple to me :)

Well I could, but there are other fixes in the current version that would be useful and don't seem to break anything else too...

Comment 4 Huzaifa S. Sidhpurwala 2012-07-05 08:29:45 UTC
(In reply to comment #3)
> (In reply to comment #2)
> > (In reply to comment #1)
> > > I have a fix for this (basically updating the package in EPEL-6 to the same
> > > as was built for Fedora in April), which I could build if tremble is OK with
> > > that.
> > 
> > Ok you could backport the patch, the patch looks pretty simple to me :)
> 
> Well I could, but there are other fixes in the current version that would be
> useful and don't seem to break anything else too...

Then you really should go ahead with the upgrade!

Comment 5 Paul Howarth 2012-07-05 08:33:54 UTC
Well I would, except that I'm not the EPEL-6 maintainer, tremble is. Now I could do it as a provenpackager but I'd run the risk of making a change that the maintainer didn't want to do for some reason, so I'd prefer to see some feedback from tremble first really.

Comment 6 Red Hat Production Operations 2012-07-05 13:13:50 UTC
Paul, sorry I missed your comment,

I was trying to backport the fix, but I hit a few issues and a lack of time.  Go for the update.

FYI: I am not overly protective of "my" packages, feel free to update especially for Security bugs.

Comment 7 Paul Howarth 2012-07-05 13:15:19 UTC
(In reply to comment #6, by Red Hat Production Operations)
> Paul, sorry I missed your comment,
> 
> I was trying to backport the fix, but I hit a few issues and a lack of time.
> Go for the update.
> 
> FYI: I am not overly protective of "my" packages, feel free to update
> especially for Security bugs.

tremble, is that you?

Comment 8 Mark Chappell 2012-07-05 13:16:58 UTC
Oops wrong account.

Paul, sorry I missed your comment,

I was trying to backport the fix, but I hit a few issues and a lack of time.  Go for the update.

FYI: I am not overly protective of "my" packages, feel free to update especially for Security bugs.

Comment 9 Fedora Update System 2012-07-05 14:20:47 UTC
perl-YAML-LibYAML-0.38-3.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/perl-YAML-LibYAML-0.38-3.el6

Comment 10 Fedora Update System 2012-07-21 00:22:15 UTC
perl-YAML-LibYAML-0.38-3.el6 has been pushed to the Fedora EPEL 6 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.