Mageia 2020-0275: perl-YAML security update
Summary
Updated perl-YAML package fixes security vulnerability: This update enforces that $LoadCode must be enabled to use the feature of evaluating typeglobs, because with the typeglob feature you would be able to set the variable $YAML::LoadCode from a YAML file, and that would be a
References
- https://bugs.mageia.org/show_bug.cgi?id=25900
- https://metacpan.org/dist/YAML/changes
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/MKJQXJGMWYVDZSQFDB4EJ2WNJ6RU65J4/
Resolution
MGASA-2020-0275 - Updated perl-YAML packages fix security vulnerability
SRPMS
- 7/core/perl-YAML-1.300.0-1.mga7