Simon Ferquel discovered that the Go yaml package incorrectly handled
certain YAML documents. If a user or an automated system were tricked
into opening a specially crafted input file, a remote attacker could
possibly use this issue to cause the system to crash, resulting in
a denial of service. (CVE-2021-4235)
It was discovered that the Go yaml package incorrectly handled
certain large YAML documents. If a user or an automated system were tricked
into opening a specially crafted input file, a remote attacker could
possibly use this issue to cause the system to crash, resulting in
a denial of service. (CVE-2022-3064)
More Stories
CVE-2022-35908
Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent. Read More
thunderbird-115.3.1-1.fc39
FEDORA-2023-1afa208698 Packages in this update: thunderbird-115.3.1-1.fc39 Update description: Update to 115.3.1 ; https://www.thunderbird.net/en-US/thunderbird/115.3.1/releasenotes/ ; https://www.mozilla.org/en-US/security/advisories/mfsa2023-44/ Update to 115.3.0 ; https://www.thunderbird.net/en-US/thunderbird/115.3.0/releasenotes/...
libptytty-2.0-4.el7 rxvt-unicode-9.31-1.el7
FEDORA-EPEL-2023-a99c56df6a Packages in this update: libptytty-2.0-4.el7 rxvt-unicode-9.31-1.el7 Update description: The last update for rxvt-unicode stripped it down to just the...
libvpx-1.13.0-5.fc39
FEDORA-2023-10ff82e497 Packages in this update: libvpx-1.13.0-5.fc39 Update description: Security fix for CVE-2023-5217 Read More
libvpx-1.12.0-3.fc37
FEDORA-2023-f696934fbf Packages in this update: libvpx-1.12.0-3.fc37 Update description: Security fix for CVE-2023-5217 Read More
libvpx-1.13.0-5.fc38
FEDORA-2023-c896cf87db Packages in this update: libvpx-1.13.0-5.fc38 Update description: Security fix for CVE-2023-5217 Read More