Fedora alert FEDORA-2018-1c8b49fbc7 (perl-Module-CoreList)
From: | updates@fedoraproject.org | |
To: | package-announce@lists.fedoraproject.org | |
Subject: | [SECURITY] Fedora 27 Update: perl-Module-CoreList-5.20180414-1.fc27 | |
Date: | Sat, 21 Apr 2018 03:41:26 +0000 (UTC) | |
Message-ID: | <20180421034126.C6D2A61753B9@bastion01.phx2.fedoraproject.org> |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2018-1c8b49fbc7 2018-04-21 03:38:52.949252 -------------------------------------------------------------------------------- Name : perl-Module-CoreList Product : Fedora 27 Version : 5.20180414 Release : 1.fc27 URL : http://search.cpan.org/dist/Module-CoreList/ Summary : What modules are shipped with versions of perl Description : Module::CoreList provides information on which core and dual-life modules are shipped with each version of perl. -------------------------------------------------------------------------------- Update Information: This release provides Perl 5.24.4 that fixes a heap buffer overflow in the pack() function and two overflows in the regular expression engine. -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 16 2018 Petr Pisar <ppisar@redhat.com> - 1:5.20180414-1 - 5.20180414_26 bump * Mon Jan 22 2018 Jitka Plesnikova <jplesnik@redhat.com> - 1:5.20180120-1 - 5.20180120 bump * Fri Dec 22 2017 Petr Pisar <ppisar@redhat.com> - 1:5.20171220-1 - 5.20171220 bump * Tue Nov 21 2017 Petr Pisar <ppisar@redhat.com> - 1:5.20171120-1 - 5.20171120 bump * Mon Oct 23 2017 Jitka Plesnikova <jplesnik@redhat.com> - 1:5.20171020-1 - 5.20171020 bump -------------------------------------------------------------------------------- References: [ 1 ] Bug #1547783 - CVE-2018-6797 perl: heap write overflow in regcomp.c https://bugzilla.redhat.com/show_bug.cgi?id=1547783 [ 2 ] Bug #1547779 - CVE-2018-6798 perl: heap read overflow in regexec.c https://bugzilla.redhat.com/show_bug.cgi?id=1547779 [ 3 ] Bug #1547772 - CVE-2018-6913 perl: heap buffer overflow in pp_pack.c https://bugzilla.redhat.com/show_bug.cgi?id=1547772 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-1c8b49fbc7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org