MGASA-2014-0098
Dashboard / Vulnerabilities / MGASA-2014-0098
Summary: Updated perl-CGI-Application packages fix CVE-2013-7329
Details: Updated perl-CGI-Application package fixes security vulnerability: When applications using CGI::Application overload setup(), which is normally the case, CGI::Application since version 4.19 has dump_html as a default run-mode unless the application explicitly redefines it. This unexpectedly dumps a complete set of web query data and server environment information as an error page, thus leaking information (CVE-2013-7329).
References: https://advisories.mageia.org/MGASA-2014-0098.html, http://openwall.com/lists/oss-security/2014/02/20/1, https://bugzilla.redhat.com/show_bug.cgi?id=1067180, https://bugs.mageia.org/show_bug.cgi?id=12827
Affected packages
Package
Name: perl-CGI-Application
Purl: pkg:rpm/mageia/perl-CGI-Application?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
