FreeBSD 14 — py27-yaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide
🟢 Low ⏱ 5–15 min Last verified: 16 March 2025 Affected versions: FreeBSD 14 📖 ~4 min read • Source: FreeBSD VuXML VuXML topic: py-yaml — FullLoader (still) exploitable for arbitrary command execution Related CVEs: CVE-2017-18342 CVE-2020-1747 Upstream summary: Riccardo Schirone (https://github.com/ret2libc) reports: In FullLoader python/object/new constructor, implemented by construct_python_object_apply, has support for setting […]