[Git][security-tracker-team/security-tracker][master] Replace oss-security posts for libyaml-syck-perl with cpansec advisories
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 17 20:57:03 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f365eabb by Salvatore Bonaccorso at 2026-07-17T21:54:43+02:00
Replace oss-security posts for libyaml-syck-perl with cpansec advisories
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -841,19 +841,19 @@ CVE-2019-25764 (**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Ac
NOT-FOR-US: ASUS
CVE-2026-57077 (YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read v ...)
- libyaml-syck-perl <unfixed> (bug #1142267)
- NOTE: https://www.openwall.com/lists/oss-security/2026/07/17/4
+ NOTE: https://lists.security.metacpan.org/cve-announce/msg/41898716/
NOTE: Fixed by: https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b (1.47)
CVE-2026-57076 (YAML::Syck versions before 1.47 for Perl allow a heap use-after-free v ...)
- libyaml-syck-perl <unfixed> (bug #1142267)
- NOTE: https://www.openwall.com/lists/oss-security/2026/07/17/3
+ NOTE: https://lists.security.metacpan.org/cve-announce/msg/41898718/
NOTE: Fixed by: https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b (1.47)
CVE-2026-57075 (YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read v ...)
- libyaml-syck-perl <unfixed> (bug #1142267)
- NOTE: https://www.openwall.com/lists/oss-security/2026/07/17/2
+ NOTE: https://lists.security.metacpan.org/cve-announce/msg/41898720/
NOTE: Fixed by: https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b (1.47)
CVE-2026-13713 (YAML::Syck versions before 1.47 for Perl allow a use-after-free and do ...)
- libyaml-syck-perl <unfixed> (bug #1142267)
- NOTE: https://www.openwall.com/lists/oss-security/2026/07/17/1
+ NOTE: https://lists.security.metacpan.org/cve-announce/msg/41898719/
NOTE: Fixed by: https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b (1.47)
CVE-2026-62321
- netatalk <unfixed> (bug #1142270)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f365eabb0fa132be34ae4624621f454b9dc00b40
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f365eabb0fa132be34ae4624621f454b9dc00b40
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260717/e7ea68ae/attachment.htm>
More information about the debian-security-tracker-commits
mailing list