ELSA-2010-0458

ELSA-2010-0458 - perl security update

Type:SECURITY
Severity:MODERATE
Release Date:2010-06-07

Description



[4:5.8.8-32.el5.1]
- third version of patch fix change of behaviour of rmtree for common user
- Resolves: rhbz#597203

[4:5.8.8-32.el5]
- rhbz#595416 change documentation of File::Path
- Related: rhbz#591167

[4:5.8.8-31.el5]
- remove previous fix
- Related: rhbz#591167

[4:5.8.8-30.el5]
- change config to file on Util.so
- Related: rhbz#594406

[4:5.8.8-29.el5]
- CVE-2008-5302 - use latest patch without Cwd module
- 507378 because of our paths we need to overload old Util.so in case customer installed
Scalar::Util from cpan. In this case we marked new Util.so as .rpmnew.
- Related: rhbz#591167
- Resolves: rhbz#594406

[4:5.8.8-28.el5]
- CVE-2008-5302 perl: File::Path rmtree race condition (CVE-2005-0448)
reintroduced after upstream rebase to 5.8.8-1
- CVE-2010-1168 perl Safe: Intended restriction bypass via object references
- CVE-2010-1447 Safe 2.26 and earlier: Intended restriction bypass via Perl
object references in code executed outside safe compartment
- Related: rhbz#591167


Related CVEs


CVE-2008-5302
CVE-2008-5303
CVE-2010-1168
CVE-2010-1447

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 5 (i386) perl-5.8.8-32.el5_5.1.src.rpmbf4dcb37e9b469454087cdff3c8bbdf4ELBA-2014-1761
perl-5.8.8-32.el5_5.1.i386.rpmd59e8b72bbe5622429b4341c075dad6fELBA-2014-1761
perl-suidperl-5.8.8-32.el5_5.1.i386.rpm5b2d8dd3642278146382d90ce3015c84ELBA-2014-1761
Oracle Linux 5 (ia64) perl-5.8.8-32.el5_5.1.src.rpmbf4dcb37e9b469454087cdff3c8bbdf4ELBA-2014-1761
perl-5.8.8-32.el5_5.1.ia64.rpme9a72661a797cb449589ef5fe0a67612ELBA-2014-1761
perl-suidperl-5.8.8-32.el5_5.1.ia64.rpm0474a9054a80378c7f6d47ba34881a06ELBA-2014-1761
Oracle Linux 5 (x86_64) perl-5.8.8-32.el5_5.1.src.rpmbf4dcb37e9b469454087cdff3c8bbdf4ELBA-2014-1761
perl-5.8.8-32.el5_5.1.x86_64.rpm13bdcefc440faac53db04b39240c06deELBA-2014-1761
perl-suidperl-5.8.8-32.el5_5.1.x86_64.rpm7ea92db32baa2f191a720f1e79e70f90ELBA-2014-1761



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete