Release date:
Updated on: 2012-03-12
Affected Systems:
Perl YAML: LibYAML 0.x
Description:
--------------------------------------------------------------------------------
Perl is a high-level, general, literal, and dynamic programming language.
Perl's YAML: LibYAML module has multiple implementation vulnerabilities that can be exploited by malicious users to control applications.
This vulnerability occurs when parsing YAML files, the functions "Load ()", "load_node ()", "load_mapping ()", and "load_sequence ()" (LibYAML/perl_libyaml.c) format string error.
<* Source: Dominic Hargreaves
Link: http://secunia.com/advisories/48317/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Perl
----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.perl.com