Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: perl
Date: Fri, 20 Dec 2002 14:59:10
Message-Id: 20021220144715.6491B5764@mail2.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200212-6
6 - - --------------------------------------------------------------------
7
8 PACKAGE : perl
9 SUMMARY : broken safe compartment
10 DATE    : 2002-12-20 14:12 UTC
11 EXPLOIT : local
12
13 - - --------------------------------------------------------------------
14
15 Quote from http://use.perl.org/articles/02/10/06/1118222.shtml?tid=5
16
17 "A security hole has been discovered in Safe.pm. When a Safe
18 compartment has already been used, there's no guarantee that it's safe
19 any longer, because there's a way for code executed within the Safe
20 compartment to alter its operation mask. (Thus, programs that use a
21 Safe compartment only once aren't affected by this bug"
22
23 Mor information is available at
24 http://groups.google.com/groups?threadm=rt-17744-39131.3.96370682846239%40bugs6.perl.org
25
26 SOLUTION
27
28 It is recommended that all Gentoo Linux users who are running
29 sys-devel/perl-5.6.1-r9 or sys-devel/5.8.0-r5 and earlier update their
30 systems as follows:
31
32 emerge rsync
33 emerge perl
34 emerge clean
35
36 ALTERNATIVE SOLUTION
37
38 If you don't want to or can't upgrade your perl package right away,
39 you can emerge dev-perl/Safe to accomplish the same solution as above.
40
41 - - --------------------------------------------------------------------
42 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
43 mcummings@g.o
44 - - --------------------------------------------------------------------
45 -----BEGIN PGP SIGNATURE-----
46 Version: GnuPG v1.2.1 (GNU/Linux)
47
48 iD8DBQE+Ay13fT7nyhUpoZMRAnnkAJ9rZaVQgc8/6JBljqKRq2uO9wj1eACggdJc
49 vvE5MXez0xeSi4EC30BYnSM=
50 =WQ3V
51 -----END PGP SIGNATURE-----