Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 29: FEDORA-2018-f6a5b71464 Critical: mod_perl Exec Risk

fedora
Calendar Grey September 21, 2018
Dist Fedora Esm H88
The Fedora 29 patch addresses CVE-2011-2767, enhancing security by disabling non-server-grade Perl script execution.
This release fixes CVE-2011-2767 vulnerability (an arbitrary Perl code execution in the context of the httpd server) by disabling sections in non-server- level configuration...

Summary

Mod_perl incorporates a Perl interpreter into the Apache web server,

so that the Apache web server can directly execute Perl code.

Mod_perl links the Perl run-time library into the Apache web server and

provides an object-oriented Perl interface for Apache's C language

API. The end result is a quicker CGI script turnaround process, since

no external Perl interpreter has to be started.

Install mod_perl if you're installing the Apache web server and you'd

like for it to directly incorporate a Perl interpreter.

This release fixes CVE-2011-2767 vulnerability (an arbitrary Perl code execution

in the context of the httpd server) by disabling sections in non-server-level configuration.

[ 1 ] Bug #1623265 - CVE-2011-2767 mod_perl: arbitrary Perl code execution in the context of the user account via a user-owned .htaccess

https://bugzilla.redhat.com/show_bug.cgi?id=1623265

su -c 'dnf upgrade --advisory FEDORA-2018-f6a5b71464' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 29
Version: 2.0.10
Release: 13.fc29
Summary: An embedded Perl interpreter for the Apache HTTP Server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here