LWN.net Logo

cobbler: code execution

Package(s):cobbler CVE #(s):CVE-2011-4952 CVE-2011-4954
Created:April 24, 2012 Updated:April 25, 2012
Description: From the openSUSE advisory:

Specially crafted YAML could allow attackers to execute arbitrary code due to the use of yaml.load instead of yaml.safe_load.

Alerts:
openSUSE openSUSE-SU-2012:0557-1 2012-04-24
openSUSE openSUSE-SU-2012:0639-1 2012-05-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds