OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Daniel Ahlberg (aliz_at_gentoo.org)
Date: Fri Dec 20 2002 - 08:47:28 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - - --------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200212-6
    - - --------------------------------------------------------------------

    PACKAGE : perl
    SUMMARY : broken safe compartment
    DATE    : 2002-12-20 14:12 UTC
    EXPLOIT : local

    - - --------------------------------------------------------------------

    Quote from http://use.perl.org/articles/02/10/06/1118222.shtml?tid=5

    "A security hole has been discovered in Safe.pm. When a Safe
    compartment has already been used, there's no guarantee that it's safe
    any longer, because there's a way for code executed within the Safe
    compartment to alter its operation mask. (Thus, programs that use a
    Safe compartment only once aren't affected by this bug"

    Mor information is available at
    http://groups.google.com/groups?threadm=rt-17744-39131.3.96370682846239%40bugs6.perl.org

    SOLUTION

    It is recommended that all Gentoo Linux users who are running
    sys-devel/perl-5.6.1-r9 or sys-devel/5.8.0-r5 and earlier update their
    systems as follows:

    emerge rsync
    emerge perl
    emerge clean

    ALTERNATIVE SOLUTION

    If you don't want to or can't upgrade your perl package right away,
    you can emerge dev-perl/Safe to accomplish the same solution as above.

    - - --------------------------------------------------------------------
    alizgentoo.org - GnuPG key is available at www.gentoo.org/~aliz
    mcummingsgentoo.org
    - - --------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.1 (GNU/Linux)

    iD8DBQE+Ay13fT7nyhUpoZMRAnnkAJ9rZaVQgc8/6JBljqKRq2uO9wj1eACggdJc
    vvE5MXez0xeSi4EC30BYnSM=
    =WQ3V
    -----END PGP SIGNATURE-----