freebsd-ports/devel/py-yaml
Josh Paetzel 954d218c29 Update to 5.3.1
This release contains a security fix for CVE-2020-1747. FullLoader was still
exploitable for arbitrary command execution.
https://bugzilla.redhat.com/show_bug.cgi?id=1807367

Thanks to Riccardo Schirone (https://github.com/ret2libc) for both reporting
this and providing the fixes to resolve it.

  - https://github.com/yaml/pyyaml/pull/386

PR:	245937
Submitted by:	daniel.engberg.lists@pyret.net
MFH:	2020Q2
Security:	http://vuxml.freebsd.org/freebsd/aae8fecf-888e-11ea-9714-08002718de91.html
2020-04-27 20:22:42 +00:00
..
distinfo
Makefile
pkg-descr
pkg-plist