-
Notifications
You must be signed in to change notification settings - Fork 1.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2017-18342 Breaks beets #3221
Comments
This was fixed in be12a89, we just need to backport this. |
Removed more unsafe calls in #3225 |
Thanks for letting us know about this! Now that we've removed the remaining unsafe YAML calls, I guess all that we can do is push out a new release of beets for packaging. @sampsyo I'm not sure what your plans are in terms of work that should be wrapped up before releasing, but maybe this issue is a good motivation to make that happen sooner rather than later :) |
Problem
CVE-2017-18342, related to YAML parsing in Python, breaks beets on Gentoo. There are two related downstream bugs 1, 2.
Running this command in verbose (
-vv
) mode:Led to this problem:
Setup
The text was updated successfully, but these errors were encountered: