Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: 2010-88: perl: Multiple Vulnerabilities
Posted by Benjamin D. Thomas
Multiple vulnerabilities in Safe.pm module in perl have been fixed.
------------------------------------------------------------------------
Pardus Linux Security Advisory 2010-88 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2010-06-24
Severity: 3
Type: Local
------------------------------------------------------------------------
Summary
======
Multiple vulnerabilities in Safe.pm module in perl have been fixed.
Description
==========
CVE-2010-1168:
The Safe (aka Safe.pm) module before 2.25 for Perl allows
context-dependent attackers to bypass intended (1) Safe::reval and (2)
Safe::rdo access restrictions, and inject and execute arbitrary code,
via vectors involving implicitly called methods and implicitly blessed
objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods,
related to "automagic methods."
Affected packages:
Pardus 2009:
perl, all before 5.10.1-29-11
Resolution
=========
There are update(s) for perl. You can update them via Package Manager or
with a single command from console:
pisi up perl
References
=========
* http://bugs.pardus.org.tr/show_bug.cgi?id080
------------------------------------------------------------------------