Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora 26: 2018-0050f7c0d1 Critical: Perl Buffer Overflows Fixes

fedora
Calendar Grey April 25, 2018
Dist Fedora Esm H88
The release of Perl 5.24.4 for Fedora 26 addresses significant vulnerabilities related to buffer overflow issues within the regular expression processing and the pack utility.
This release provides Perl 5.24.4 that fixes a heap buffer overflow in the pack() function and two overflows in the regular expression engine.

Summary

Module::CoreList provides information on which core and dual-life modules

are shipped with each version of perl.

This release provides Perl 5.24.4 that fixes a heap buffer overflow in the

pack() function and two overflows in the regular expression engine.

* Mon Apr 16 2018 Petr Pisar - 1:5.20180414-1

- 5.20180414_24 bump

* Mon Jan 22 2018 Jitka Plesnikova - 1:5.20180120-1

- 5.20180120 bump

* Fri Dec 22 2017 Petr Pisar - 1:5.20171220-1

- 5.20171220 bump

* Tue Nov 21 2017 Petr Pisar - 1:5.20171120-1

- 5.20171120 bump

* Mon Oct 23 2017 Jitka Plesnikova - 1:5.20171020-1

- 5.20171020 bump

* Mon Sep 25 2017 Petr Pisar - 1:5.20170923-1

- 5.20170923 bump

* Thu Sep 21 2017 Petr Pisar - 1:5.20170920-1

- 5.20170920 bump

* Tue Aug 22 2017 Petr Pisar - 1:5.20170821-1

- 5.20170821 bump

* Fri Jul 21 2017 Petr Pisar - 1:5.20170720-1

- 5.20170720 bump

* Mon Jul 17 2017 Petr Pisar - 1:5.20170715-1

- 5.20170715 bump

[ 1 ] Bug #1547783 - CVE-2018-6797 perl: heap write overflow in regcomp.c

https://bugzilla.redhat.com/show_bug.cgi?id=1547783

[ 2 ] Bug #1547779 - CVE-2018-6798 perl: heap read overflow in regexec.c

https://bugzilla.redhat.com/show_bug.cgi?id=1547779

[ 3 ] Bug #1547772 - CVE-2018-6913 perl: heap buffer overflow in pp_pack.c

https://bugzilla.redhat.com/show_bug.cgi?id=1547772

su -c 'dnf upgrade --advisory FEDORA-2018-0050f7c0d1' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 26
Version: 5.20180414
Release: 1.fc26
Summary: What modules are shipped with versions of perl

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here