Input validation error in PyYAML - CVE-2017-18342
Published: October 15, 2019
Vulnerability identifier: #VU21781
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-18342
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to insufficient validation of user-supplied input in the "yaml.load()" API (yaml.safe_load is not used). A remote attacker can execute arbitrary code on the target system.
Affected software
PyYAML
Gentoo Linux
Anolis OS
Fedora
Cloud Pak for Security (CP4S)
python38-wcwidth
python38-PyMySQL
python38-pluggy
python38-Cython
python38-wheel-wheel
python38-wheel
python38-markupsafe
python38-asn1crypto
python38-atomicwrites
python38-scipy
python38-pysocks
python38-py
python38-six
python38-cffi
python38-numpy-doc
python38-numpy
python38-numpy-f2py
python38-urllib3
python38-pyparsing
python38-babel
python38-cryptography
python38-psycopg2-tests
python38-psycopg2-doc
python38-psycopg2
python38-idna
python38-jinja2
python38-pycparser
python38-requests
python38-chardet
python38-rpm-macros
python38
python38-debug
python38-devel
python38-test
python38-idle
python38-libs
python38-tkinter
python38-ply
python38-lxml
python38-pytest
python38-mod_wsgi
PyYAML
python38-pyyaml
python38-psutil
python38-more-itertools
python38-packaging
python38-attrs
python38-pip-wheel
python38-pip
python38-setuptools
python38-setuptools-wheel
python38-pytz
IBM Security Verify Access
IBM Cloud Pak for Business Automation
Gentoo Linux
Anolis OS
Fedora
Cloud Pak for Security (CP4S)
python38-wcwidth
python38-PyMySQL
python38-pluggy
python38-Cython
python38-wheel-wheel
python38-wheel
python38-markupsafe
python38-asn1crypto
python38-atomicwrites
python38-scipy
python38-pysocks
python38-py
python38-six
python38-cffi
python38-numpy-doc
python38-numpy
python38-numpy-f2py
python38-urllib3
python38-pyparsing
python38-babel
python38-cryptography
python38-psycopg2-tests
python38-psycopg2-doc
python38-psycopg2
python38-idna
python38-jinja2
python38-pycparser
python38-requests
python38-chardet
python38-rpm-macros
python38
python38-debug
python38-devel
python38-test
python38-idle
python38-libs
python38-tkinter
python38-ply
python38-lxml
python38-pytest
python38-mod_wsgi
PyYAML
python38-pyyaml
python38-psutil
python38-more-itertools
python38-packaging
python38-attrs
python38-pip-wheel
python38-pip
python38-setuptools
python38-setuptools-wheel
python38-pytz
IBM Security Verify Access
IBM Cloud Pak for Business Automation
How to mitigate CVE-2017-18342
Install updates from vendor's website.
PyYAML - update to 4.1
Cloud Pak for Security (CP4S) - update to 1.10.13.0
python38-wcwidth - update to 0.1.7-16
python38-PyMySQL - update to 0.10.1-1
python38-pluggy - update to 0.13.0-3
python38-Cython - update to 0.29.14-4
python38-wheel-wheel - update to 0.33.6-6
python38-wheel - update to 0.33.6-6
python38-markupsafe - update to 1.1.1-6
python38-asn1crypto - update to 1.2.0-3
python38-atomicwrites - update to 1.3.0-8
python38-scipy - update to 1.3.1-4
python38-pysocks - update to 1.7.1-4
python38-py - update to 1.8.0-8
python38-six - update to 1.12.0-10
python38-cffi - update to 1.13.2-3
python38-numpy-doc - update to 1.17.3-6
python38-numpy - update to 1.17.3-6
python38-numpy-f2py - update to 1.17.3-6
python38-urllib3 - update to 1.25.7-5
python38-pyparsing - update to 2.4.5-3
python38-babel - update to 2.7.0-11
python38-cryptography - update to 2.8-3
python38-psycopg2-tests - update to 2.8.4-4
python38-psycopg2-doc - update to 2.8.4-4
python38-psycopg2 - update to 2.8.4-4
python38-idna - update to 2.8-6
python38-jinja2 - update to 2.10.3-5
python38-pycparser - update to 2.19-3
python38-requests - update to 2.22.0-9
python38-chardet - update to 3.0.4-19
python38-rpm-macros - update to 3.8.12-1.0.1
python38 - update to 3.8.12-1.0.1
python38-debug - update to 3.8.12-1.0.1
python38-devel - update to 3.8.12-1.0.1
python38-test - update to 3.8.12-1.0.1
python38-idle - update to 3.8.12-1.0.1
python38-libs - update to 3.8.12-1.0.1
python38-tkinter - update to 3.8.12-1.0.1
python38-ply - update to 3.11-10
python38-lxml - update to 4.4.1-7
python38-pytest - update to 4.6.6-3
python38-mod_wsgi - update to 4.6.8-3
PyYAML - addressed in versions 5.1-1.fc28, 5.1-1.fc29, 5.1-1.fc30
python38-pyyaml - update to 5.4.1-1
python38-psutil - update to 5.6.4-4
python38-more-itertools - update to 7.2.0-5
IBM Security Verify Access - update to 10.0.7.0
python38-packaging - update to 19.2-3
python38-attrs - update to 19.3.0-3
python38-pip-wheel - update to 19.3.1-5
python38-pip - update to 19.3.1-5
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.32, 23.0.2.4
python38-setuptools - update to 41.6.0-5
python38-setuptools-wheel - update to 41.6.0-5
python38-pytz - update to 2019.3-3
Cloud Pak for Security (CP4S) - update to 1.10.13.0
python38-wcwidth - update to 0.1.7-16
python38-PyMySQL - update to 0.10.1-1
python38-pluggy - update to 0.13.0-3
python38-Cython - update to 0.29.14-4
python38-wheel-wheel - update to 0.33.6-6
python38-wheel - update to 0.33.6-6
python38-markupsafe - update to 1.1.1-6
python38-asn1crypto - update to 1.2.0-3
python38-atomicwrites - update to 1.3.0-8
python38-scipy - update to 1.3.1-4
python38-pysocks - update to 1.7.1-4
python38-py - update to 1.8.0-8
python38-six - update to 1.12.0-10
python38-cffi - update to 1.13.2-3
python38-numpy-doc - update to 1.17.3-6
python38-numpy - update to 1.17.3-6
python38-numpy-f2py - update to 1.17.3-6
python38-urllib3 - update to 1.25.7-5
python38-pyparsing - update to 2.4.5-3
python38-babel - update to 2.7.0-11
python38-cryptography - update to 2.8-3
python38-psycopg2-tests - update to 2.8.4-4
python38-psycopg2-doc - update to 2.8.4-4
python38-psycopg2 - update to 2.8.4-4
python38-idna - update to 2.8-6
python38-jinja2 - update to 2.10.3-5
python38-pycparser - update to 2.19-3
python38-requests - update to 2.22.0-9
python38-chardet - update to 3.0.4-19
python38-rpm-macros - update to 3.8.12-1.0.1
python38 - update to 3.8.12-1.0.1
python38-debug - update to 3.8.12-1.0.1
python38-devel - update to 3.8.12-1.0.1
python38-test - update to 3.8.12-1.0.1
python38-idle - update to 3.8.12-1.0.1
python38-libs - update to 3.8.12-1.0.1
python38-tkinter - update to 3.8.12-1.0.1
python38-ply - update to 3.11-10
python38-lxml - update to 4.4.1-7
python38-pytest - update to 4.6.6-3
python38-mod_wsgi - update to 4.6.8-3
PyYAML - addressed in versions 5.1-1.fc28, 5.1-1.fc29, 5.1-1.fc30
python38-pyyaml - update to 5.4.1-1
python38-psutil - update to 5.6.4-4
python38-more-itertools - update to 7.2.0-5
IBM Security Verify Access - update to 10.0.7.0
python38-packaging - update to 19.2-3
python38-attrs - update to 19.3.0-3
python38-pip-wheel - update to 19.3.1-5
python38-pip - update to 19.3.1-5
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.32, 23.0.2.4
python38-setuptools - update to 41.6.0-5
python38-setuptools-wheel - update to 41.6.0-5
python38-pytz - update to 2019.3-3
External References
Related Security Bulletins
- Remote code execution in PyYAML component for Python
- Gentoo update for PyYAML
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Anolis OS update for python38:3.8 module
- Fedora 30 update for PyYAML
- Fedora 29 update for PyYAML
- Fedora 28 update for PyYAML