UbuntuUpdates.org

Package "libyaml-libyaml-perl"

Name: libyaml-libyaml-perl

Description:

Perl interface to libyaml, a YAML implementation

Latest version: 0.89+ds-1ubuntu0.24.04.1
Release: noble (24.04)
Level: security
Repository: main
Homepage: https://metacpan.org/release/YAML-LibYAML

Links


Download "libyaml-libyaml-perl"


Other versions of "libyaml-libyaml-perl" in Noble

Repository Area Version
base main 0.89+ds-1build2
updates main 0.89+ds-1ubuntu0.24.04.1

Changelog

Version: 0.89+ds-1ubuntu0.24.04.1 2025-07-09 19:37:00 UTC

  libyaml-libyaml-perl (0.89+ds-1ubuntu0.24.04.1) noble-security; urgency=medium

  * SECURITY UPDATE: file overwrite vulnerability
    - debian/patches/CVE-2025-40908.patch: use 3-arg form of open in
      LoadFile in lib/YAML/XS.pm.
    - CVE-2025-40908

 -- Marc Deslauriers <email address hidden> Tue, 08 Jul 2025 14:03:31 -0400

CVE-2025-40908 YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified



About   -   Send Feedback to @ubuntu_updates