Multiple vulnerabilities have been fixed in ruby-loofah, a Ruby library for manipulating and transforming HTML/XML documents and fragments. CVE-2022-23514 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3901-1
This release fixes CVE-2015-8853 (regexp matching hangs indefinitely on illegal UTF-8 input).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-5a9313e4b4 2016-05-06 14:23:31.381970 -------------------------------------------------------------------------------- Name : perl Product : Fedora 22 Version : 5.20.3 Release : 330.fc22 URL : https://www.perl.org/ Summary : Practical Extraction and Report Language Description : Perl is a high-level programming language with roots in C, sed, awk and shell scripting. Perl is good at handling processes and files, and is especially good at handling text. Perl's hallmarks are practicality and efficiency. While it is used to do a lot of different things, Perl's most common applications are system administration utilities and web programming. A large proportion of the CGI scripts on the web are written in Perl. You need the perl package installed on your system so that your system can handle Perl scripts. Install this package if you want to program in Perl or enable your system to handle Perl scripts. -------------------------------------------------------------------------------- Update Information: This release fixes CVE-2015-8853 (regexp matching hangs indefinitely on illegal UTF-8 input). -------------------------------------------------------------------------------- References: [ 1 ] Bug #1329106 - CVE-2015-8853 perl: regexp matching hangs indefinitely on illegal UTF-8 input https://bugzilla.redhat.com/show_bug.cgi?id=1329106 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update perl' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Security fix for CVE-2014-6585 CVE-2014-6591 CVE-2014-7923 CVE-2014-7926 CVE-2014-9654. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-16314 2015-10-13 12:51:16.882949 -------------------------------------------------------------------------------- Name : icu Product : Fedora 22 Version : 54.1 Release : 4.fc22 URL : https://icu-project.org/ Summary : International Components for Unicode Description : Tools and utilities for developing with icu. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2014-6585 CVE-2014-6591 CVE-2014-7923 CVE-2014-7926 CVE-2014-9654 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1183645 - CVE-2014-6585 ICU: font parsing OOB read (OpenJDK 2D, 8055489) https://bugzilla.redhat.com/show_bug.cgi?id=1183645 [ 2 ] Bug #1183646 - CVE-2014-6591 ICU: font parsing OOB read (OpenJDK 2D, 8056276) https://bugzilla.redhat.com/show_bug.cgi?id=1183646 [ 3 ] Bug #1185202 - CVE-2014-7923 ICU: regexp engine missing look-behind expression range check https://bugzilla.redhat.com/show_bug.cgi?id=1185202 [ 4 ] Bug #1185205 - CVE-2014-7926 ICU: regexp engine incorrect handling of a zero length quantifier https://bugzilla.redhat.com/show_bug.cgi?id=1185205 [ 5 ] Bug #1190129 - CVE-2014-9654 icu: insufficient size limit checks in regular expression compiler https://bugzilla.redhat.com/show_bug.cgi?id=1190129 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update icu' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.