CVE-2017-18640

Priority
Description
The Alias feature in SnakeYAML 1.18 allows entity expansion during a load
operation, a related issue to CVE-2003-1564.
Notes
amurrayUpstream dispute this as a valid CVE - https://bitbucket.org/asomov/snakeyaml/issues/377/allow-configuration-for-preventing-billion#comment-55227358 - and they added a test-case for this type of attack of 2 years ago https://bitbucket.org/asomov/snakeyaml/commits/04378d05777d21d114a9cdc24976ad49c8919222 so this would appear to be a non-issue
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):needs-triage
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 19.10 (Eoan Ermine):needs-triage
Ubuntu 20.04 (Focal Fossa):needs-triage
More Information

Updated: 2020-01-29 18:47:38 UTC (commit 40f18bf14da5fb50662e1f861ea594a462b207fe)