LWN.net Logo

Fedora alert FEDORA-2012-15490 (perl-HTML-Template-Pro)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 17 Update: perl-HTML-Template-Pro-0.9509-1.fc17
Date:  Sun, 14 Oct 2012 03:50:56 +0000
Message-ID:  <20121014035056.B029620CBB@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2012-15490 2012-10-06 03:24:35 -------------------------------------------------------------------------------- Name : perl-HTML-Template-Pro Product : Fedora 17 Version : 0.9509 Release : 1.fc17 URL : http://search.cpan.org/dist/HTML-Template-Pro/ Summary : Perl/XS module to use HTML Templates from CGI scripts Description : A fast and lightweight C/Perl+XS HTML Template engine implementation. -------------------------------------------------------------------------------- Update Information: This version of HTML::Template::Pro fixes a cross-site scripting (XSS) vulnerability in the module. http://www.openwall.com/lists/oss-security/2011/12/19/1 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=652587 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4616 -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 4 2012 Emmanuel Seyman <emmanuel@seyman.fr> - 0.9509-1 - Update to 0.9509 (CVE-2011-4616, #773453) - Add default perl filter -------------------------------------------------------------------------------- References: [ 1 ] Bug #768822 - CVE-2011-4616 perl-HTML-Template-Pro: XSS issue https://bugzilla.redhat.com/show_bug.cgi?id=768822 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update perl-HTML-Template-Pro' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds