Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-10219 http://linux.oracle.com/errata/ELSA-2024-10219.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: perl-App-cpanminus-1.7044-6.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-File-pushd-1.014-6.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-Module-CPANfile-1.1002-7.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-Parse-PMFile-0.41-7.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-String-ShellQuote-1.04-24.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-App-cpanminus-1.7044-6.module+el8.10.0+90448+352bb180.noarch.rpm perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90448+352bb180.noarch.rpm perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90448+352bb180.noarch.rpm perl-File-pushd-1.014-6.module+el8.10.0+90448+352bb180.noarch.rpm perl-Module-CPANfile-1.1002-7.module+el8.10.0+90448+352bb180.noarch.rpm perl-Parse-PMFile-0.41-7.module+el8.10.0+90448+352bb180.noarch.rpm perl-String-ShellQuote-1.04-24.module+el8.10.0+90448+352bb180.noarch.rpm perl-App-cpanminus-1.7044-6.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-File-pushd-1.014-6.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-Module-CPANfile-1.1002-7.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-Parse-PMFile-0.41-7.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-String-ShellQuote-1.04-24.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-App-cpanminus-1.7044-6.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-File-pushd-1.014-6.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-Module-CPANfile-1.1002-7.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-Parse-PMFile-0.41-7.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-String-ShellQuote-1.04-24.module+el8.10.0+90444+3175cdc0.noarch.rpm aarch64: perl-App-cpanminus-1.7044-6.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-File-pushd-1.014-6.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-Module-CPANfile-1.1002-7.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-Parse-PMFile-0.41-7.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-String-ShellQuote-1.04-24.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-App-cpanminus-1.7044-6.module+el8.10.0+90448+352bb180.noarch.rpm perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90448+352bb180.noarch.rpm perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90448+352bb180.noarch.rpm perl-File-pushd-1.014-6.module+el8.10.0+90448+352bb180.noarch.rpm perl-Module-CPANfile-1.1002-7.module+el8.10.0+90448+352bb180.noarch.rpm perl-Parse-PMFile-0.41-7.module+el8.10.0+90448+352bb180.noarch.rpm perl-String-ShellQuote-1.04-24.module+el8.10.0+90448+352bb180.noarch.rpm perl-App-cpanminus-1.7044-6.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-File-pushd-1.014-6.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-Module-CPANfile-1.1002-7.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-Parse-PMFile-0.41-7.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-String-ShellQuote-1.04-24.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-App-cpanminus-1.7044-6.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-File-pushd-1.014-6.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-Module-CPANfile-1.1002-7.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-Parse-PMFile-0.41-7.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-String-ShellQuote-1.04-24.module+el8.10.0+90444+3175cdc0.noarch.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//perl-App-cpanminus-1.7044-6.module+el8.10.0+90447+dcd0bd0b.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90447+dcd0bd0b.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90447+dcd0bd0b.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-File-pushd-1.014-6.module+el8.10.0+90447+dcd0bd0b.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-Module-CPANfile-1.1002-7.module+el8.10.0+90447+dcd0bd0b.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-Parse-PMFile-0.41-7.module+el8.10.0+90447+dcd0bd0b.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-String-ShellQuote-1.04-24.module+el8.10.0+90447+dcd0bd0b.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-App-cpanminus-1.7044-6.module+el8.10.0+90448+352bb180.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90448+352bb180.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90448+352bb180.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-File-pushd-1.014-6.module+el8.10.0+90448+352bb180.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-Module-CPANfile-1.1002-7.module+el8.10.0+90448+352bb180.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-Parse-PMFile-0.41-7.module+el8.10.0+90448+352bb180.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-String-ShellQuote-1.04-24.module+el8.10.0+90448+352bb180.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-App-cpanminus-1.7044-6.module+el8.10.0+90446+cd5c22a3.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90446+cd5c22a3.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-File-pushd-1.014-6.module+el8.10.0+90446+cd5c22a3.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-Module-CPANfile-1.1002-7.module+el8.10.0+90446+cd5c22a3.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-Parse-PMFile-0.41-7.module+el8.10.0+90446+cd5c22a3.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-String-ShellQuote-1.04-24.module+el8.10.0+90446+cd5c22a3.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-App-cpanminus-1.7044-6.module+el8.10.0+90444+3175cdc0.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90444+3175cdc0.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90444+3175cdc0.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-File-pushd-1.014-6.module+el8.10.0+90444+3175cdc0.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-Module-CPANfile-1.1002-7.module+el8.10.0+90444+3175cdc0.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-Parse-PMFile-0.41-7.module+el8.10.0+90444+3175cdc0.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-String-ShellQuote-1.04-24.module+el8.10.0+90444+3175cdc0.src.rpm Related CVEs: CVE-2024-45321 Description of changes: perl-App-cpanminus [1.7044-6] - Patch the code to use https instead of http (CVE-2024-45321) perl-CPAN-DistnameInfo perl-CPAN-Meta-Check perl-File-pushd perl-Module-CPANfile perl-Parse-PMFile perl-String-ShellQuote perl-App-cpanminus [1.7044-6] - Patch the code to use https instead of http (CVE-2024-45321) perl-CPAN-DistnameInfo perl-CPAN-Meta-Check perl-File-pushd perl-Module-CPANfile perl-Parse-PMFile perl-String-ShellQuote perl-App-cpanminus [1.7044-6] - Patch the code to use https instead of http (CVE-2024-45321) perl-CPAN-Meta-Check perl-File-pushd perl-Module-CPANfile perl-Parse-PMFile perl-String-ShellQuote perl-App-cpanminus [1.7044-6] - Patch the code to use https instead of http (CVE-2024-45321) perl-CPAN-DistnameInfo perl-CPAN-Meta-Check perl-File-pushd perl-Module-CPANfile perl-Parse-PMFile perl-String-ShellQuote _______________________________________________ El-errata mailing list
Patch the code to use https instead of http (CVE-2024-45321). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-78e43b4de6 2024-10-09 00:46:39.270360 -------------------------------------------------------------------------------- Name : perl-App-cpanminus Product : Fedora 39 Version : 1.7047 Release : 2.fc39 URL : https://metacpan.org/dist/App-cpanminus Summary : Get, unpack, build and install CPAN modules Description : Why? It's dependency free, requires zero configuration, and stands alone but it's maintainable and extensible with plug-ins and friendly to shell scripting. When running, it requires only 10 MB of RAM. -------------------------------------------------------------------------------- Update Information: Patch the code to use https instead of http (CVE-2024-45321) -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 26 2024 Jitka Plesnikova - 1.7047-2 - Patch the code to use https instead of http (CVE-2024-45321) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2308438 - CVE-2024-45321 perl-App-cpanminus: From NVD collector [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2308438 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-78e43b4de6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Fix for CVE-2023-7101 (unvalidated input can lead to arbitrary code execution vulnerability).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-921f6975c2 2024-01-08 01:23:05.713087 -------------------------------------------------------------------------------- Name : perl-Spreadsheet-ParseExcel Product : Fedora 39 Version : 0.6600 Release : 1.fc39 URL : https://metacpan.org/dist/Spreadsheet-ParseExcel Summary : Extract information from an Excel file Description : The Spreadsheet::ParseExcel module can be used to read information from an Excel 95-2003 file. -------------------------------------------------------------------------------- Update Information: Fix for CVE-2023-7101 (unvalidated input can lead to arbitrary code execution vulnerability). -------------------------------------------------------------------------------- ChangeLog: * Sat Dec 30 2023 Paul Howarth - 0.6600-1 - Update to 0.66 - Fix for CVE-2023-7101 (unvalidated input can lead to arbitrary code execution vulnerability) https://github.com/runrig/spreadsheet-parseexcel/issues/33 - Use author-independent source URL - Use SPDX-format license tag - No longer need to fix document file permissions - Fix permissions verbosely - Don't assume "pm" suffix on manpage files -------------------------------------------------------------------------------- References: [ 1 ] Bug #2255871 - CVE-2023-7101 perl-Spreadsheet-ParseExcel: unvalidated input can lead to arbitrary code execution vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=2255871 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-921f6975c2' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.