A new update is available for Red Hat Enterprise Linux. Here the announcement:
"-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
=====================================================================
Red Hat Security Advisory
Synopsis: Important: perl security update
Advisory ID: RHSA-2008:0532-01
Product: Red Hat Application Stack
Advisory URL: https://rhn.redhat.com/errata/RHSA-2008-0532.html
Issue date: 2008-06-17
CVE Names: CVE-2008-1927
=====================================================================
1. Summary:
Updated perl packages that fix a security issue are now available for Red
Hat Application Stack v1.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
2. Relevant releases/architectures:
Red Hat Application Stack v1 for Enterprise Linux AS (v.4) - i386, x86_64
Red Hat Application Stack v1 for Enterprise Linux ES (v.4) - i386, x86_64
3. Description:
Perl is a high-level programming language commonly used for system
administration utilities and Web programming.
A flaw was found in Perl's regular expression engine. A specially crafted
regular expression with Unicode characters could trigger a buffer overflow,
causing Perl to crash, or possibly execute arbitrary code with the
privileges of the user running Perl. (CVE-2008-1927)
Users of perl are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.
4. Solution:
Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.
This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188
5. Bugs fixed (http://bugzilla.redhat.com/):
443928 - CVE-2008-1927 perl: heap corruption by regular expressions with utf8 characters
6. Package List:
Red Hat Application Stack v1 for Enterprise Linux AS (v.4):
Source:
ftp://updates.redhat.com/enterprise/4AS/en/RHWAS/SRPMS/perl-5.8.8-6.el4s1_3.src.rpm
i386:
perl-5.8.8-6.el4s1_3.i386.rpm
perl-debuginfo-5.8.8-6.el4s1_3.i386.rpm
perl-suidperl-5.8.8-6.el4s1_3.i386.rpm
x86_64:
perl-5.8.8-6.el4s1_3.x86_64.rpm
perl-debuginfo-5.8.8-6.el4s1_3.x86_64.rpm
perl-suidperl-5.8.8-6.el4s1_3.x86_64.rpm
Red Hat Application Stack v1 for Enterprise Linux ES (v.4):
Source:
ftp://updates.redhat.com/enterprise/4ES/en/RHWAS/SRPMS/perl-5.8.8-6.el4s1_3.src.rpm
i386:
perl-5.8.8-6.el4s1_3.i386.rpm
perl-debuginfo-5.8.8-6.el4s1_3.i386.rpm
perl-suidperl-5.8.8-6.el4s1_3.i386.rpm
x86_64:
perl-5.8.8-6.el4s1_3.x86_64.rpm
perl-debuginfo-5.8.8-6.el4s1_3.x86_64.rpm
perl-suidperl-5.8.8-6.el4s1_3.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://www.redhat.com/security/team/key/#package
7. References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1927
http://www.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is . More contact
details at https://www.redhat.com/security/team/contact/
Copyright 2008 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)
iD8DBQFIV+LaXlSAg2UNWIIRAnqOAJ4i980+slEe2a/YJyQie+6IzyFgLQCeNj6m
kc2ruoFFTbQnl/+PLezRQSY=
=ZawF
-----END PGP SIGNATURE-----
"
CESA-2008:0522 Important CentOS 3 s390(x) perl - security update
This entry was posted
on 6:36 PM
.
Archives
-
▼
2008
(457)
-
▼
June
(48)
- The Perfect Desktop - OpenSUSE 11 (GNOME)
- USN-620-1: OpenSSL vulnerabilities
- CESA-2008:0290 Critical CentOS 5 x86_64 samba Update
- ruby (SSA:2008-179-01)
- Mot ships new Linux phones
- CESA-2008:0519 Important CentOS 5 x86_64 kernel Up...
- CESA-2008:0519 Important CentOS 5 i386 kernel Update
- Ubuntu MID Edition ships
- CESA-2008:0290 Critical CentOS 5 i386 samba Update
- Battle of the Titans - Mandriva vs openSUSE: The R...
- Open source phone goes mass-market
- RHSA-2008:0133-01 Moderate: IBMJava2 security update
- RHSA-2008:0508-01 Important: kernel security and b...
- Embedding Python In Apache2 With mod_python (Debia...
- CESA-2008:0556 Important CentOS 4 i386 freetype - ...
- CESA-2008:0556 Important CentOS 3 i386 freetype - ...
- CESA-2008:0558-01: Important CentOS 2 i386 freetyp...
- How To Set Up WebDAV With MySQL Authentication On ...
- GLSA 200806-07 X.Org X server: Multiple vulnerabi...
- USN-612-11: openssl-blacklist update
- Linux robot plays frenetic clarinet
- PCLinuxOS GNOME Review
- GNOME 2.23.4 Released
- Linux prominent in chip show awards
- GLSA 200806-06 Evolution: User-assisted execution...
- openSUSE 11.0 released
- CESA-2008:0503 Important CentOS 4 s390(x) xorg-x11...
- Damn Small Linux 4.4 Review
- CESA-2008:0522 Important CentOS 3 s390(x) perl - s...
- USN-617-1: Samba vulnerabilities
- GLSA 200806-05 cbrPager: User-assisted execution ...
- RHSA-2008:0532-01 Important: perl security update
- Mozilla previews Firefox Mobile
- GLSA 200806-04 rdesktop: Multiple vulnerabilities
- USN-612-10: OpenVPN regression
- CESA-2008:0498 Moderate CentOS 3 s390(x) cups - se...
- CESA-2008:0498 Moderate CentOS 3 i386 cups - secur...
- Linux macro benchmark tool stabilizes
- CESA-2008:0498 Moderate CentOS 3 x86_64 cups - sec...
- CESA-2008:0516 Critical CentOS 3 i386 evolution - ...
- GLSA 200806-02 libxslt: Execution of arbitrary code
- RHSA-2008:0498-01 Moderate: cups security update
- GLSA 200805-22 MPlayer: User-assisted execution o...
- CESA-2008:0288 Critical CentOS 4 x86_64 samba Update
- CESA-2008:0288 Critical CentOS 3 s390(x) samba - s...
- CESA-2008:0288 Critical CentOS 4 s390(x) samba - s...
- CESA-2008:0288-01: Critical CentOS 2 i386 samba se...
- RHSA-2008:0288-01 Critical: samba security update
-
▼
June
(48)