-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2019-1911b73cee 2019-05-08 01:11:39.966075 --------------------------------------------------------------------------------
Name : perl-YAML Product : Fedora 30 Version : 1.28 Release : 1.fc30 URL : https://metacpan.org/release/YAML Summary : YAML Ain't Markup Language (tm) Description : The YAML.pm module implements a YAML Loader and Dumper based on the YAML 1.0 specification (http://www.yaml.org/spec/). YAML is a generic data serialization language that is optimized for human readability. It can be used to express the data structures of most modern programming languages, including Perl. For information on the YAML syntax, please refer to the YAML specification.
-------------------------------------------------------------------------------- Update Information:
This update enforces that $LoadCode must be enabled to use the feature of evaluating typeglobs, because with the typeglob feature you would be able to set the variable $YAML::LoadCode from a YAML file, and that would be a security issue. -------------------------------------------------------------------------------- ChangeLog:
* Sun Apr 28 2019 Paul Howarth paul@city-fan.org - 1.28-1 - Update to 1.28 - Security fix: only enable loading globs when $LoadCode is set (GH#213) - Modernize spec using %{make_build} and %{make_install} -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1703790 - perl-YAML-1.28 is available https://bugzilla.redhat.com/show_bug.cgi?id=1703790 --------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-1911b73cee' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------