shield
Security update for perl
SUSE-SLE-SERVER-12-SP2-2017-1903
This update for perl fixes the following issues: Security issues fixed: - CVE-2017-12837: Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\N{}' escape and the case-insensitive modifier. (bnc#1057724) - CVE-2017-12883: Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of service (application crash) via a crafted regular expression with an invalid '\N{U+...}' escape. (bnc#1057721) - CVE-2017-6512: Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic. (bnc#1047178) Bug fixes: - backport set_capture_string changes from upstream (bsc#999735) - reformat baselibs.conf as source validator workaround
-
Release DateNov 24 2017
-
References
-
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Server 12.2 aarch64
-
Packages
SUSE Linux Enterprise Server for SAP Applications 12.2 ppc64le
-
Packages
SUSE Linux Enterprise Server 12.2 s390x
-
Packagesperl
The Perl interpreterperl-32bit5.18.2-12.3.1 lock rpm lock src
The Perl interpreterperl-base5.18.2-12.3.1 lock rpm
The Perl interpreterperl-doc5.18.2-12.3.1 lock rpm
Perl Documentation5.18.2-12.3.1 lock rpm
SUSE Linux Enterprise Server 12.2 x86_64
-
Packagesperl
The Perl interpreterperl-32bit5.18.2-12.3.1 lock rpm lock src
The Perl interpreterperl-base5.18.2-12.3.1 lock rpm
The Perl interpreterperl-doc5.18.2-12.3.1 lock rpm
Perl Documentation5.18.2-12.3.1 lock rpm