Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

openSUSE 11.4: Important Perl Update for DoS and Code Injection

opensuse
Calendar Grey March 20, 2013
Dist Opensuse Esm H88
This update fixes security vulnerabilities in Perl for openSUSE. Users must update to secure their systems and follow the steps provided to ensure safety
An update that fixes three vulnerabilities is now available.

Description

Perl was updated to fix 3 security issues:

- fix rehash denial of service (compute time) [bnc#804415]

[CVE-2013-1667]

- improve CGI crlf escaping [bnc#789994] [CVE-2012-5526]

- sanitize input in Maketext.pm to avoid code injection

[bnc#797060] [CVE-2012-6329]

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 11.4:

zypper in -t patch 2013-46

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 11.4 (i586 x86_64):

perl-5.12.3-11.36.1

perl-base-5.12.3-11.36.1

perl-base-debuginfo-5.12.3-11.36.1

perl-debuginfo-5.12.3-11.36.1

perl-debugsource-5.12.3-11.36.1

- openSUSE 11.4 (x86_64):

perl-32bit-5.12.3-11.36.1

perl-base-32bit-5.12.3-11.36.1

perl-base-debuginfo-32bit-5.12.3-11.36.1

perl-debuginfo-32bit-5.12.3-11.36.1

- openSUSE 11.4 (noarch):

perl-doc-5.12.3-11.36.1

- openSUSE 11.4 (ia64):

perl-base-debuginfo-x86-5.12.3-11.36.1

perl-base-x86-5.12.3-11.36.1

perl-debuginfo-x86-5.12.3-11.36.1

perl-x86-5.12.3-11.36.1

References

https://www.suse.com/security/cve/CVE-2012-5526.html

https://www.suse.com/security/cve/CVE-2012-6329.html

https://www.suse.com/security/cve/CVE-2013-1667.html

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2013:0502-1
Rating: important
Affected Products: openSUSE 11.4

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here