Input validation error in PyYAML - CVE-2020-1747
Published: March 9, 2020 / Updated: July 15, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input when processing untrusted YAML files passed via the "full_load" method or with the "FullLoader" loader. A remote attacker can pass specially crafted input to the application and execute arbitrary code by abusing the python/object/new constructor.
Affected software
Gentoo Linux
SUSE OpenStack Cloud
Anolis OS
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server - AUS
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Oracle Solaris
SUSE Manager Tools
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Module for Advanced Systems Management
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
Opensuse
openEuler
Fedora
Cloud Pak for Security (CP4S)
py3-yaml (Alpine package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
python38-PyMySQL
python38-Cython
python38-wheel-wheel
python38-wheel
python38-markupsafe
python38-asn1crypto
python38-scipy
python38-pysocks
python38-six
python38-cffi
python38-numpy
python38-numpy-doc
python38-numpy-f2py
python38-urllib3
python38-babel
python38-cryptography
python38-psycopg2-doc
python38-psycopg2-tests
python38-psycopg2
python38-idna
python38-jinja2
python38-pycparser
python38-requests
python38-chardet
python38-rpm-macros
python38-libs
python38-tkinter
python38-test
python38-idle
python38-devel
python38-debug
python38
python38-ply
python38-lxml
python38-mod_wsgi
python-PyYAML
python-PyYAML-debuginfo
python-PyYAML-debugsource
python3-PyYAML
python2-PyYAML-debuginfo
python2-PyYAML
python3-PyYAML-debuginfo
python2-pyyaml
python3-pyyaml
pyyaml-debuginfo
pyyaml-debugsource
PyYAML
pyyaml
dev-python/pyyaml
python38-pyyaml
python38-psutil
python38-pip-wheel
python38-pip
python38-setuptools
python38-setuptools-wheel
python38-pytz
EMC ECS
IBM Cloud Pak for Business Automation
Juniper Cloud Native Router
Junos cRPD
How to mitigate CVE-2020-1747
Cloud Pak for Security (CP4S) - update to 1.10.7.0
py3-yaml (Alpine package) - update to 5.3.1-r0
python38-PyMySQL - update to 0.10.1-1
python38-Cython - update to 0.29.14-4
python38-wheel-wheel - update to 0.33.6-5
python38-wheel - update to 0.33.6-5
python38-markupsafe - update to 1.1.1-6
python38-asn1crypto - update to 1.2.0-3
python38-scipy - update to 1.3.1-4
python38-pysocks - update to 1.7.1-4
python38-six - update to 1.12.0-10
python38-cffi - update to 1.13.2-3
python38-numpy - update to 1.17.3-5
python38-numpy-doc - update to 1.17.3-5
python38-numpy-f2py - update to 1.17.3-5
python38-urllib3 - update to 1.25.7-4
python38-babel - update to 2.7.0-10
python38-cryptography - update to 2.8-3
python38-psycopg2-doc - update to 2.8.4-4
python38-psycopg2-tests - update to 2.8.4-4
python38-psycopg2 - update to 2.8.4-4
python38-idna - update to 2.8-6
python38-jinja2 - update to 2.10.3-4
python38-pycparser - update to 2.19-3
python38-requests - update to 2.22.0-9
python38-chardet - update to 3.0.4-19
EMC ECS - update to 3.5.0.1
python38-rpm-macros - update to 3.8.6-3
python38-libs - update to 3.8.6-3
python38-tkinter - update to 3.8.6-3
python38-test - update to 3.8.6-3
python38-idle - update to 3.8.6-3
python38-devel - update to 3.8.6-3
python38-debug - update to 3.8.6-3
python38 - update to 3.8.6-3
python38-ply - update to 3.11-10
python38-lxml - update to 4.4.1-5
python38-mod_wsgi - update to 4.6.8-3
python-PyYAML - addressed in versions 5.1.2-26.15.1, 5.3.1-28.6.1
python-PyYAML-debuginfo - addressed in versions 5.1.2-26.15.1, 5.1.2-150000.3.6.1, 5.3.1-28.6.1
python-PyYAML-debugsource - addressed in versions 5.1.2-26.15.1, 5.1.2-150000.3.6.1, 5.3.1-28.6.1
python3-PyYAML - addressed in versions 5.1.2-26.15.1, 5.1.2-150000.3.6.1, 5.3.1-28.6.1
python2-PyYAML-debuginfo - update to 5.1.2-150000.3.6.1
python2-PyYAML - update to 5.1.2-150000.3.6.1
python3-PyYAML-debuginfo - addressed in versions 5.1.2-150000.3.6.1, 5.3.1-28.6.1
python2-pyyaml - update to 5.3.1-1
python3-pyyaml - addressed in versions 5.3.1-1, 5.3.1-4
pyyaml-debuginfo - addressed in versions 5.3.1-1, 5.3.1-4
pyyaml-debugsource - addressed in versions 5.3.1-1, 5.3.1-4
PyYAML - addressed in versions 5.3.1-1.fc30, 5.3.1-1.fc31, 5.3.1-1.fc32, 5.4.1-1.fc32, 5.4.1-1.fc33
pyyaml - update to 5.3.1-4
dev-python/pyyaml - update to 5.4
python38-pyyaml - update to 5.4.1-1
python38-psutil - update to 5.6.4-3
python38-pip-wheel - update to 19.3.1-1
python38-pip - update to 19.3.1-1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.32, 23.0.2.4
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
python38-setuptools - update to 41.6.0-4
python38-setuptools-wheel - update to 41.6.0-4
python38-pytz - update to 2019.3-3
External References
Related Security Bulletins
- Remote code execution in PyYAML parser and emitter for Python
- OpenSUSE Linux update for python-PyYAML
- OpenSUSE Linux update for python-PyYAML
- Oracle Solaris security update for third party software (July 2020)
- Input validation error in py3-yaml (Alpine package)
- Red Hat Enterprise Linux 8 update for the python38:3.8 module
- Red Hat Enterprise Linux 8.4 update for the python38:3.8 and python38-devel:3.8 modules
- SUSE update for python-PyYAML
- SUSE update for python-PyYAML
- SUSE update for python-PyYAML
- Multiple vulnerabilities in Dell EMC ECS
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Gentoo update for PyYAML
- openEuler 20.03 LTS update for pyyaml-5.3.1-1
- openEuler 20.03 LTS SP1 update for PyYAML
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Fedora 33 update for PyYAML
- Fedora 32 update for PyYAML
- Anolis OS update for python38:3.8 module
- Fedora 32 update for PyYAML
- Fedora 31 update for PyYAML
- Fedora 30 update for PyYAML