Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Fedora 27: FEDORA-2018-1c8b49fbc7 Moderate: perl Heap Overflow Fix

fedora
Calendar Grey April 21, 2018
Dist Fedora Esm H88
Python 3.6.8 patches in Ubuntu 18.04 fix potential memory leaks promoting system stability.
This release provides Perl 5.24.4 that fixes a heap buffer overflow in the pack() function and two overflows in the regular expression engine.

Summary

Module::CoreList provides information on which core and dual-life modules

are shipped with each version of perl.

This release provides Perl 5.24.4 that fixes a heap buffer overflow in the

pack() function and two overflows in the regular expression engine.

* Mon Apr 16 2018 Petr Pisar - 1:5.20180414-1

- 5.20180414_26 bump

* Mon Jan 22 2018 Jitka Plesnikova - 1:5.20180120-1

- 5.20180120 bump

* Fri Dec 22 2017 Petr Pisar - 1:5.20171220-1

- 5.20171220 bump

* Tue Nov 21 2017 Petr Pisar - 1:5.20171120-1

- 5.20171120 bump

* Mon Oct 23 2017 Jitka Plesnikova - 1:5.20171020-1

- 5.20171020 bump

[ 1 ] Bug #1547783 - CVE-2018-6797 perl: heap write overflow in regcomp.c

https://bugzilla.redhat.com/show_bug.cgi?id=1547783

[ 2 ] Bug #1547779 - CVE-2018-6798 perl: heap read overflow in regexec.c

https://bugzilla.redhat.com/show_bug.cgi?id=1547779

[ 3 ] Bug #1547772 - CVE-2018-6913 perl: heap buffer overflow in pp_pack.c

https://bugzilla.redhat.com/show_bug.cgi?id=1547772

su -c 'dnf upgrade --advisory FEDORA-2018-1c8b49fbc7' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Product: Fedora 27
Version: 5.20180414
Release: 1.fc27
Summary: What modules are shipped with versions of perl

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here