Denial of Service in Perl (Aktualisierung)
ID: | USN-3478-2 |
Distribution: | Ubuntu |
Plattformen: | Ubuntu 12.04 ESM |
Datum: | Mo, 13. November 2017, 22:10 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12883 |
Applikationen: | Perl |
Update von: | Zwei Probleme in Perl |
Originalnachricht |
|
--===============8629190841748537520== Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="=-h7Obx9yuqWec5AYhWWor" --=-h7Obx9yuqWec5AYhWWor Content-Type: text/plain; charset="UTF-8 Content-Transfer-Encoding: quoted-printable ========================================================================== Ubuntu Security Notice USN-3478-2 November 13, 2017 perl vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: Perl could be made to crash if it received specially crafted input. Software Description: - perl: Practical Extraction and Report Language Details: USN-3478-1 fixed two vulnerabilities in Perl. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: Jakub Wilk discovered that Perl incorrectly handled certain regular expressions. An attacker could use this issue to cause Perl to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2017-12883) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: perl 5.14.2-6ubuntu2.6 In general, a standard system update will make all the necessary changes. References: https://www.ubuntu.com/usn/usn-3478-2 https://www.ubuntu.com/usn/usn-3478-1 CVE-2017-12883 --=-h7Obx9yuqWec5AYhWWor Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAABCAAGBQJaCepxAAoJEEW851uECx9pI/QP/3B/kYAW/6MdvazOAuQvmB7L 3KA3dI6PcbOMTAa+0gIHLdKUES75rh/bdyRwzEUarRBSx4nQpdrhnyY0nqfi9ccP B3UA+OgSiZW0pNuLJmOoyFJ2Aeoy81HrE7NRqGTSFRGNbKny/nZEFjSenWwI7gKm f3Dv8WzU51/Zeylc/TRkhOvA5MngdWFT4uKJeVJ2viJoJNaZH6EslkH1QJGQK3+e 61+Z8X3kMv7nR7L7kLCgYZRRPXYUJAmvLjF9i+JvA3k3i9fUyTrp8akbkbTnZS4d 7m34LQ1gY1j/gsNbJCXPCJGpk2lMjD7elRf+41TroezNHhlUOdXH0WCOkgRl+Vn8 ui8F6T/gdqaNkWO9ZK50R0eybe46ouUtTd3r8g8P3h2wyB+EDGN+nVC/tNDqMzLg to8YzFyLNkINsO/yRpMAEgFcXj98DlcGPwu1m8C6pXmhi4BGqVFz7DbgI0OHXijT 96Gdm6F3avPMnVWRMqaxyS2Ni/ixpmcSZM8PrdjOaaf+QQxx9GVnEOaejiK2tdXR 3P7DqgxI+H251JZQgF8uZwR7X18AhAuhwuEzZDJU2lC/ET4b7uVEc9TULFBRJ4JS DRhqGnXBG0qAqWDaTSCvmMT0sOPiRPq+vhDDKbCG/Ep2qnvE3ZODJu3/lB4PTEEc qec91XqkhOARje354lle =241S -----END PGP SIGNATURE----- --=-h7Obx9yuqWec5AYhWWor-- --===============8629190841748537520== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5 LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj dXJpdHktYW5ub3VuY2UK --===============8629190841748537520==-- |