drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Denial of Service in libemail-address-perl
Name: |
Denial of Service in libemail-address-perl |
|
ID: |
DSA-2969-1 |
|
Distribution: |
Debian |
|
Plattformen: |
Debian sid, Debian wheezy, Debian jessie |
|
Datum: |
Sa, 28. Juni 2014, 12:45 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0477 |
|
Applikationen: |
libemail-address-perl |
|
Originalnachricht |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512
- ------------------------------------------------------------------------- Debian Security Advisory DSA-2969-1 security@debian.org http://www.debian.org/security/ Salvatore Bonaccorso June 27, 2014 http://www.debian.org/security/faq - -------------------------------------------------------------------------
Package : libemail-address-perl CVE ID : CVE-2014-0477
Bastian Blank reported a denial of service vulnerability in Email::Address, a Perl module for RFC 2822 address parsing and creation. Email::Address::parse used significant time on parsing empty quoted strings. A remote attacker able to supply specifically crafted input to an application using Email::Address for parsing, could use this flaw to mount a denial of service attack against the application.
For the stable distribution (wheezy), this problem has been fixed in version 1.895-1+deb7u1.
For the testing distribution (jessie), this problem has been fixed in version 1.905-1.
For the unstable distribution (sid), this problem has been fixed in version 1.905-1.
We recommend that you upgrade your libemail-address-perl packages.
Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1
iQIcBAEBCgAGBQJTrbc/AAoJEAVMuPMTQ89EdL4P/2QLmNtcvcdrx8RUoAa50J2e EagJVN0b5SPtj+jiBEQ1aF89Dn09dvGnhgDac0D2ADq3xAYX3v7Z/ss0wE1+IIf0 c9AFCtlVx5gzrNWBbZHnwksux8/KJowKXLPIu+C68WaZiPeuDpv7H6Nyn/HhgBnY 33Wm9HzmLg+EmvIXBC8jmY0ZEN86n4ax0NOzud79zmNpSjhN/uy1dgRq4BF6cZwt 7wv68y9ZiyKP+9FOsW3A81Zs5TZO2/xqZcZqTiC4YD1se5ggnB+/dYm4IGDe3HJ3 /uA8EhCjxSYE3VoSmcqtVpteko0t6+jBoF7zg0RU8z1ndwU5ClGTetst5qeTuHgm y6aTM87CgsHc2sZbi9sk5e7DSGSSapKPBIBduti5H1iPBVuvMZcNc4FsXeWa+wmt DOCpIz5mOCRRzeAQL73dt2y7nUG0tK+RMXtckus4kNOEEewkKcmlkI8RGw+ttyFt 4YBx0E4nE6Ya4R0swe37A+g0vQAf3Y2qJ/L29qNiL6YDhgtGuoJfg22SAfkJhzWK Qf2thkvRbLyo7dJCG2QAHqHHgdsEWAtvtTwIv8n+6Y9NJuY4P+SzQvp6AbXt85oS XvYp/Jd43XJlEnTvP32f4N7XME1PNPcHQKom7XKCCUsVt/ffYlS0AKW5iJ4eJUS6 D4JVJ+FBLDn9zKyW7FDH =ZR/s -----END PGP SIGNATURE-----
-- To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org Archive: https://lists.debian.org/E1X0asA-0005BZ-Ki@master.debian.org
|
|
|
|