Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Ubuntu: 2878-1 Critical Perl Taint Attribute Bypass Threat

Ubuntu Large Esm H500
Perl incorrectly handled the taint attribute.
=========================================================================Ubuntu Security Notice USN-2878-1
January 21, 2016

perl vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 15.04

Summary:

Perl incorrectly handled the taint attribute.

Software Description:
- perl: Practical Extraction and Report Language

Details:

David Golden discovered that the canonpath function in the Perl File::Spec
module did not properly preserve the taint attribute. An attacker could
possibly use this issue to bypass the taint protection mechanism.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  perl                            5.20.2-6ubuntu0.1

Ubuntu 15.04:
  perl                            5.20.2-2ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2878-1
  CVE-2015-8607

Package Information:
  https://launchpad.net/ubuntu/+source/perl/5.20.2-6ubuntu0.1
  https://launchpad.net/ubuntu/+source/perl/5.20.2-2ubuntu0.1


Ubuntu: 2878-1 Critical Perl Taint Attribute Bypass Threat

ubuntu
Calendar Grey January 21, 2016
Dist Ubuntu Esm H88
Python flaw in Fedora reveals variable scope concern. Patch suggested for impacted versions, February 15, 2017.
Perl incorrectly handled the taint attribute.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: perl 5.20.2-6ubuntu0.1 Ubuntu 15.04: perl 5.20.2-2ubuntu0.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2878-1

CVE-2015-8607

Severity
critical
Lowest
Low
Medium
High
Critical

January 21, 2016

Package Information

https://launchpad.net/ubuntu/+source/perl/5.20.2-6ubuntu0.1 https://launchpad.net/ubuntu/+source/perl/5.20.2-2ubuntu0.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here