--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2025-b882a0a154
2025-10-26 00:46:54.767005+00:00
--------------------------------------------------------------------------------

Name        : perl-YAML-Syck
Product     : Fedora EPEL 10.2
Version     : 1.36
Release     : 1.el10_2
URL         : https://metacpan.org/release/YAML-Syck
Summary     : Fast, lightweight YAML loader and dumper
Description :
This module provides a Perl interface to the libsyck data serialization
library. It exports the Dump and Load functions for converting Perl data
structures to YAML strings, and the other way around.

--------------------------------------------------------------------------------
Update Information:

This update addresses a flaw in which processing a specially-crafted YAML
document could lead to accessing information outside of the document itself and
hence potential information disclosure.
--------------------------------------------------------------------------------
ChangeLog:

* Sat Oct 11 2025 Paul Howarth <[email protected]> - 1.36-1
- Update to 1.36
  - Address memory corruption leading to 'str' value being set on empty keys
* Fri Oct 10 2025 Paul Howarth <[email protected]> - 1.35-1
- Update to 1.35
  - Address parsing error related to string detection on read for empty strings
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> - 
1.34-18
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon Jul  7 2025 Jitka Plesnikova <[email protected]> - 1.34-17
- Perl 5.42 rebuild
* Sat Jan 18 2025 Paul Howarth <[email protected]> - 1.34-16
- Build using -std=gnu17 since ancient code does not compile with -std=c23
* Sat Jan 18 2025 Fedora Release Engineering <[email protected]> - 
1.34-15
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Fri Jul 19 2024 Fedora Release Engineering <[email protected]> - 
1.34-14
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Mon Jun 10 2024 Jitka Plesnikova <[email protected]> - 1.34-13
- Perl 5.40 rebuild
* Thu Jan 25 2024 Fedora Release Engineering <[email protected]> - 
1.34-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Fedora Release Engineering <[email protected]> - 
1.34-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2404559 - CVE-2025-11683 perl-YAML-Syck: YAML::Syck potential 
Information Disclosure [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2404559
--------------------------------------------------------------------------------

This update can be installed with the "yum" update programs.  Use
su -c 'yum update perl-YAML-Syck' at the command line.
For more information, refer to "YUM", available at
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7\
/html/System_Administrators_Guide/ch-yum.html

All packages are signed with the Fedora EPEL GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
epel-package-announce mailing list -- 
[email protected]
To unsubscribe send an email to 
[email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to