• [SECURITY] [DSA 2267-1] perl security update

    From Moritz Muehlenhoff@1:229/2 to All on Fri Jul 1 20:10:01 2011
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2267-1 [email protected] http://www.debian.org/security/ Moritz Muehlenhoff
    July 01, 2011 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : perl
    Vulnerability : restriction bypass
    Problem type : local
    Debian-specific: no
    CVE ID : CVE-2010-1447
    Debian Bug : 631529

    It was discovered that Perl's Safe module - a module to compile and
    execute code in restricted compartments - could by bypassed.

    Please note that this update is known to break Petal, an XML-based
    templating engine (shipped with Debian 6.0/Squeeze in the package libpetal-perl, see http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=582805
    for details). A fix is not yet available. If you use Petal, you might
    consider to put the previous Perl packages on hold.

    For the oldstable distribution (lenny), this problem has been fixed in
    version 5.10.0-19lenny5.

    For the stable distribution (squeeze), this problem has been fixed in
    version 5.10.1-17squeeze2.

    For the unstable distribution (sid), this problem has been fixed in
    version 5.12.3-1.

    We recommend that you upgrade your perl packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.11 (GNU/Linux)

    iEYEARECAAYFAk4OCOMACgkQXm3vHE4uylpFjwCgxNO0AgBmr0EM17E3rbK4Yxfo 2/gAoIuX2QExRCbSywe476I8kyKsojEq
    =Lcl2
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)