MGASA-2014-0389
Dashboard / Vulnerabilities / MGASA-2014-0389
MGASA-2014-0389
Summary: Updated perl-Email-Address packages fix security vulnerabilities
Details: Updated perl-Email-Address package fixes security vulnerability: The parse function in Email::Address module before 1.905 for Perl uses an inefficient regular expression, which allows remote attackers to cause a denial of service (CPU consumption) via an empty quoted string in an RFC 2822 address (CVE-2014-0477). The Email::Address module before 1.904 for Perl uses an inefficient regular expression, which allows remote attackers to cause a denial of service (CPU consumption) via vectors related to "backtracking into the phrase" (CVE-2014-4720).
References: https://advisories.mageia.org/MGASA-2014-0389.html, https://bugs.mageia.org/show_bug.cgi?id=13541, https://www.debian.org/security/2014/dsa-2969
Affected packages
Package
Name: perl-Email-Address
Purl: pkg:rpm/mageia/perl-Email-Address?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
