MGASA-2020-0275

Source
https://advisories.mageia.org/MGASA-2020-0275.html
Import Source
https://advisories.mageia.org/MGASA-2020-0275.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0275
Published
2020-07-05T08:46:44Z
Modified
2026-04-16T04:25:49Z
Summary
Updated perl-YAML packages fix security vulnerability
Details

Updated perl-YAML package fixes security vulnerability:

This update enforces that $LoadCode must be enabled to use the feature of evaluating typeglobs, because with the typeglob feature you would be able to set the variable $YAML::LoadCode from a YAML file, and that would be a security issue.

The perl-YAML package has been updated to version 1.30, fixing this issue and other bugs.

References
Credits

Affected packages

Mageia:7 / perl-YAML

Package

Name
perl-YAML
Purl
pkg:rpm/mageia/perl-YAML?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.300.0-1.mga7

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2020-0275.json"