GLSA: perl

From: Daniel Ahlberg (aliz@gentoo.org)
Date: 12/20/02

  • Next message: Shutters, Mike: "RE: Foundstone Research Labs Advisory - Multiple Exploitable Buff er Overflows in Winamp (fwd)"
    From: Daniel Ahlberg <aliz@gentoo.org>
    Date: Fri, 20 Dec 2002 15:47:28 +0100
    To: bugtraq@securityfocus.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - - --------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200212-6
    - - --------------------------------------------------------------------

    PACKAGE : perl
    SUMMARY : broken safe compartment
    DATE    : 2002-12-20 14:12 UTC
    EXPLOIT : local

    - - --------------------------------------------------------------------

    Quote from http://use.perl.org/articles/02/10/06/1118222.shtml?tid=5

    "A security hole has been discovered in Safe.pm. When a Safe
    compartment has already been used, there's no guarantee that it's safe
    any longer, because there's a way for code executed within the Safe
    compartment to alter its operation mask. (Thus, programs that use a
    Safe compartment only once aren't affected by this bug"

    Mor information is available at
    http://groups.google.com/groups?threadm=rt-17744-39131.3.96370682846239%40bugs6.perl.org

    SOLUTION

    It is recommended that all Gentoo Linux users who are running
    sys-devel/perl-5.6.1-r9 or sys-devel/5.8.0-r5 and earlier update their
    systems as follows:

    emerge rsync
    emerge perl
    emerge clean

    ALTERNATIVE SOLUTION

    If you don't want to or can't upgrade your perl package right away,
    you can emerge dev-perl/Safe to accomplish the same solution as above.

    - - --------------------------------------------------------------------
    aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz
    mcummings@gentoo.org
    - - --------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.1 (GNU/Linux)

    iD8DBQE+Ay13fT7nyhUpoZMRAnnkAJ9rZaVQgc8/6JBljqKRq2uO9wj1eACggdJc
    vvE5MXez0xeSi4EC30BYnSM=
    =WQ3V
    -----END PGP SIGNATURE-----


  • Quantcast