This update to version 1.26 fixes an issue where only the prefix of the hostname was checked if there was no wildcard present, so for example www.example.org would match a certificate starting with www.example.org . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-7435 2009-07-11 02:40:16 -------------------------------------------------------------------------------- Name : perl-IO-Socket-SSL Product : Fedora 11 Version : 1.26 Release : 1.fc11 URL : https://metacpan.org/dist/IO-Socket-SSL Summary : Perl library for transparent SSL Description : This module is a true drop-in replacement for IO::Socket::INET that uses SSL to encrypt data before it is transferred to a remote server or client. IO::Socket::SSL supports all the extra features that one needs to write a full-featured SSL client or server application: multiple SSL contexts, cipher selection, certificate verification, and SSL version selection. As an extra bonus, it works perfectly with mod_perl. -------------------------------------------------------------------------------- Update Information: This update to version 1.26 fixes an issue where only the prefix of the hostname was checked if there was no wildcard present, so for example ple.org would match a certificate starting with ple.org -------------------------------------------------------------------------------- ChangeLog: * Sat Jul 4 2009 Paul Howarth - 1.26-1 - Update to 1.26 (verify_hostname_of_cert matched only the prefix for the hostname when no wildcard was given, e.g. ple.org matched against a certificate with name ple.com in it) * Fri Jul 3 2009 Paul Howarth - 1.25-1 - Update to 1.25 (fix t/nonblock.t for OS X 10.5 - CPAN RT#47240) -------------------------------------------------------------------------------- References: [ 1 ] Bug #509819 - perl-IO-Socket-SSL: incorrect checking of certificate hostnames https://bugzilla.redhat.com/show_bug.cgi?id=509819 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update perl-IO-Socket-SSL' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
XML::LibXML could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-2592-1 May 04, 2015 libxml-libxml-perl vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: XML::LibXML could be made to expose sensitive information. Software Description: - libxml-libxml-perl: Perl interface to the libxml2 library Details: Tilmann Haak discovered that XML::LibXML incorrectly handled the expand_entities parameter in certain situations. A remote attacker could possibly use this issue to access sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: libxml-libxml-perl 2.0116+dfsg-1ubuntu0.15.04.1 Ubuntu 14.10: libxml-libxml-perl 2.0116+dfsg-1ubuntu0.14.10.1 Ubuntu 14.04 LTS: libxml-libxml-perl 2.0108+dfsg-1ubuntu0.1 Ubuntu 12.04 LTS: libxml-libxml-perl 1.89+dfsg-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2592-1 CVE-2015-3451 Package Information: https://launchpad.net/ubuntu/+source/libxml-libxml-perl/2.0116+dfsg-1ubuntu0.15.04.1 https://launchpad.net/ubuntu/+source/libxml-libxml-perl/2.0116+dfsg-1ubuntu0.14.10.1 https://launchpad.net/ubuntu/+source/libxml-libxml-perl/2.0108+dfsg-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libxml-libxml-perl/1.89+dfsg-1ubuntu0.1 . A vulnerability found in the libxml-libxml-perl package of Ubuntu could potentially leak confidential information. Follow the provided steps for updates.. libxml, update instructions, exposure risk, ubuntu security. . Severity: Critical. LinuxSecurity.com Team
Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 960-2
Niko Tyni discovered that the Mail::Audit module, a Perl library for creating simple mail filters, logs to a temporary file with a predictable filename in an insecure fashion when logging is turned on, which is not the case by default.. - --------------------------------------------------------------------------Debian Security Advisory DSA 960-1
Get the latest Linux and open source security news straight to your inbox.