LWN.net Logo

Fedora alert FEDORA-2012-7777 (perl-Config-IniFiles)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 16 Update: perl-Config-IniFiles-2.72-1.fc16
Date:  Tue, 22 May 2012 02:26:12 +0000
Message-ID:  <20120522022612.A14B020B62@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2012-7777 2012-05-13 01:31:48 -------------------------------------------------------------------------------- Name : perl-Config-IniFiles Product : Fedora 16 Version : 2.72 Release : 1.fc16 URL : http://search.cpan.org/dist/Config-IniFiles/ Summary : A module for reading .ini-style configuration files Description : Config::IniFiles provides a way to have readable configuration files outside your Perl script. Configurations can be imported (inherited, stacked,...), sections can be grouped, and settings can be accessed from a tied hash. -------------------------------------------------------------------------------- Update Information: Update to 2.72, fixes CVE-2012-2451. -------------------------------------------------------------------------------- ChangeLog: * Fri May 11 2012 Tom Callaway <spot@fedoraproject.org> - 2.72-1 - update to 2.72 - notable fix: SECURITY BUG FIX: Config::IniFiles used to write to a temporary filename with a predictable name ("${filename}-new") which opens the door for potential exploits. Fixes CVE-2012-2451 * Tue Feb 21 2012 Tom Callaway <spot@fedoraproject.org> - 2.68-3 - add missing Requires: perl(IO::Scalar) >= 2.109 (bz 791078) * Fri Jan 13 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.68-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #818430 - CVE-2012-2451 perl-Config-IniFiles: insecure temporary file usage [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=818430 [ 2 ] Bug #818431 - CVE-2012-2451 perl-Config-IniFiles: insecure temporary file usage [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=818431 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update perl-Config-IniFiles' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds