Gentoo Archives: gentoo-announce

From: Chris Reffett <creffett@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] [ GLSA 201401-11 ] Perl, Locale Maketext Perl module: Multiple vulnerabilities
Date: Sun, 19 Jan 2014 16:37:40
Message-Id: 52DBFEA7.6020306@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201401-11
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Perl, Locale Maketext Perl module: Multiple vulnerabilities
9 Date: January 19, 2014
10 Bugs: #384887, #448632, #460444, #483448
11 ID: 201401-11
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Perl and Locale::Maketext
19 Perl module, the worst of which could allow a context-dependent
20 attacker to execute arbitrary code.
21
22 Background
23 ==========
24
25 Perl is Larry Wall's Practical Extraction and Report Language.
26 Locale::Maketext is a Perl module - framework for localization.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 dev-lang/perl < 5.16.3 >= 5.16.3
35 2 perl-core/locale-maketext
36 < 1.230.0 >= 1.230.0
37 -------------------------------------------------------------------
38 2 affected packages
39
40 Description
41 ===========
42
43 Multiple vulnerabilities have been discovered in Perl and
44 Locale::Maketext Perl module. Please review the CVE identifiers
45 referenced below for details.
46
47 Impact
48 ======
49
50 A context-dependent attacker could possibly execute arbitrary code with
51 the privileges of the process or cause a Denial of Service condition.
52
53 Workaround
54 ==========
55
56 There is no known workaround at this time.
57
58 Resolution
59 ==========
60
61 All Perl users should upgrade to the latest version:
62
63 # emerge --sync
64 # emerge --ask --oneshot --verbose ">=dev-lang/perl-5.16.3"
65
66 All Locale::Maketext users should upgrade to the latest version:
67
68 # emerge --sync
69 # emerge --ask --oneshot -v ">=perl-core/locale-maketext-1.230.0"
70
71 References
72 ==========
73
74 [ 1 ] CVE-2011-2728
75 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2728
76 [ 2 ] CVE-2011-2939
77 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2939
78 [ 3 ] CVE-2012-5195
79 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5195
80 [ 4 ] CVE-2013-1667
81 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1667
82
83 Availability
84 ============
85
86 This GLSA and any updates to it are available for viewing at
87 the Gentoo Security Website:
88
89 http://security.gentoo.org/glsa/glsa-201401-11.xml
90
91 Concerns?
92 =========
93
94 Security is a primary focus of Gentoo Linux and ensuring the
95 confidentiality and security of our users' machines is of utmost
96 importance to us. Any security concerns should be addressed to
97 security@g.o or alternatively, you may file a bug at
98 https://bugs.gentoo.org.
99
100 License
101 =======
102
103 Copyright 2014 Gentoo Foundation, Inc; referenced text
104 belongs to its owner(s).
105
106 The contents of this document are licensed under the
107 Creative Commons - Attribution / Share Alike license.
108
109 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature