drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Unsichere Verwendung temporärer Dateien in perl-Config-IniFiles
Name: |
Unsichere Verwendung temporärer Dateien in perl-Config-IniFiles |
|
ID: |
FEDORA-2012-7777 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 16 |
|
Datum: |
Di, 22. Mai 2012, 08:06 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2451 |
|
Applikationen: |
perl-Config-IniFiles |
|
Originalnachricht |
Name : perl-Config-IniFiles Product : Fedora 16 Version : 2.72 Release : 1.fc16 URL : http://search.cpan.org/dist/Config-IniFiles/ Summary : A module for reading .ini-style configuration files Description : Config::IniFiles provides a way to have readable configuration files outside your Perl script. Configurations can be imported (inherited, stacked,...), sections can be grouped, and settings can be accessed from a tied hash.
------------------------------------------------------------------------------- - Update Information:
Update to 2.72, fixes CVE-2012-2451. ------------------------------------------------------------------------------- - ChangeLog:
* Fri May 11 2012 Tom Callaway <spot@fedoraproject.org> - 2.72-1 - update to 2.72 - notable fix: SECURITY BUG FIX: Config::IniFiles used to write to a temporary filename with a predictable name ("${filename}-new") which opens the door for potential exploits. Fixes CVE-2012-2451 * Tue Feb 21 2012 Tom Callaway <spot@fedoraproject.org> - 2.68-3 - add missing Requires: perl(IO::Scalar) >= 2.109 (bz 791078) * Fri Jan 13 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.68-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #818430 - CVE-2012-2451 perl-Config-IniFiles: insecure temporary file usage [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=818430 [ 2 ] Bug #818431 - CVE-2012-2451 perl-Config-IniFiles: insecure temporary file usage [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=818431 ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update perl-Config-IniFiles' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce
|
|
|
|