1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
- - -------------------------------------------------------------------- |
5 |
GENTOO LINUX SECURITY ANNOUNCEMENT 200212-6 |
6 |
- - -------------------------------------------------------------------- |
7 |
|
8 |
PACKAGE : perl |
9 |
SUMMARY : broken safe compartment |
10 |
DATE : 2002-12-20 14:12 UTC |
11 |
EXPLOIT : local |
12 |
|
13 |
- - -------------------------------------------------------------------- |
14 |
|
15 |
Quote from http://use.perl.org/articles/02/10/06/1118222.shtml?tid=5 |
16 |
|
17 |
"A security hole has been discovered in Safe.pm. When a Safe |
18 |
compartment has already been used, there's no guarantee that it's safe |
19 |
any longer, because there's a way for code executed within the Safe |
20 |
compartment to alter its operation mask. (Thus, programs that use a |
21 |
Safe compartment only once aren't affected by this bug" |
22 |
|
23 |
Mor information is available at |
24 |
http://groups.google.com/groups?threadm=rt-17744-39131.3.96370682846239%40bugs6.perl.org |
25 |
|
26 |
SOLUTION |
27 |
|
28 |
It is recommended that all Gentoo Linux users who are running |
29 |
sys-devel/perl-5.6.1-r9 or sys-devel/5.8.0-r5 and earlier update their |
30 |
systems as follows: |
31 |
|
32 |
emerge rsync |
33 |
emerge perl |
34 |
emerge clean |
35 |
|
36 |
ALTERNATIVE SOLUTION |
37 |
|
38 |
If you don't want to or can't upgrade your perl package right away, |
39 |
you can emerge dev-perl/Safe to accomplish the same solution as above. |
40 |
|
41 |
- - -------------------------------------------------------------------- |
42 |
aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz |
43 |
mcummings@g.o |
44 |
- - -------------------------------------------------------------------- |
45 |
-----BEGIN PGP SIGNATURE----- |
46 |
Version: GnuPG v1.2.1 (GNU/Linux) |
47 |
|
48 |
iD8DBQE+Ay13fT7nyhUpoZMRAnnkAJ9rZaVQgc8/6JBljqKRq2uO9wj1eACggdJc |
49 |
vvE5MXez0xeSi4EC30BYnSM= |
50 |
=WQ3V |
51 |
-----END PGP SIGNATURE----- |