Lucene search

K
ubuntuUbuntuUSN-4940-1
HistoryMay 10, 2021 - 12:00 a.m.

PyYAML vulnerability

2021-05-1000:00:00
ubuntu.com
370
pyyaml
ubuntu
fullloader
remote attacker
arbitrary code
yaml parser

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.003

Percentile

68.0%

Releases

  • Ubuntu 20.10
  • Ubuntu 20.04 LTS

Packages

  • pyyaml - YAML parser and emitter for Python

Details

It was discovered that PyYAML incorrectly handled untrusted YAML files with
the FullLoader loader. A remote attacker could possibly use this issue to
execute arbitrary code.

OSVersionArchitecturePackageVersionFilename
Ubuntu20.10noarchpython3-yaml< 5.3.1-2ubuntu0.1UNKNOWN
Ubuntu20.10noarchpython3-yaml-dbg< 5.3.1-2ubuntu0.1UNKNOWN
Ubuntu20.04noarchpython-yaml< 5.3.1-1ubuntu0.1UNKNOWN
Ubuntu20.04noarchpython-yaml-dbg< 5.3.1-1ubuntu0.1UNKNOWN
Ubuntu20.04noarchpython3-yaml< 5.3.1-1ubuntu0.1UNKNOWN
Ubuntu20.04noarchpython3-yaml-dbg< 5.3.1-1ubuntu0.1UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.003

Percentile

68.0%