CVE-2012-1152

Publication date 9 September 2012

Last updated 24 July 2024


Ubuntu priority

Multiple format string vulnerabilities in the error reporting functionality in the YAML::LibYAML (aka YAML-LibYAML and perl-YAML-LibYAML) module 0.38 for Perl allow remote attackers to cause a denial of service (process crash) via format string specifiers in a (1) YAML stream to the Load function, (2) YAML node to the load_node function, (3) YAML mapping to the load_mapping function, or (4) YAML sequence to the load_sequence function.

Status

Package Ubuntu Release Status
libyaml-libyaml-perl 13.10 saucy
Fixed 0.38-2
13.04 raring
Fixed 0.38-2
12.10 quantal
Fixed 0.38-2
12.04 LTS precise
Fixed 0.38-2
11.10 oneiric Ignored end of life
11.04 natty Ignored end of life
10.10 maverick
Fixed 0.33-1+squeeze1build0.10.10.1
10.04 LTS lucid Ignored end of life
8.04 LTS hardy Not in release