MGASA-2017-0439
Dashboard / Vulnerabilities / MGASA-2017-0439
Summary: Updated perl-Catalyst-Plugin-Static-Simple package fixes security vulnerability
Details: The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a '.' character anywhere in the pathname, which differs from the intended policy of allowing access only when the filename itself has a '.' character (CVE-2017-16248).
References: https://advisories.mageia.org/MGASA-2017-0439.html, https://bugs.mageia.org/show_bug.cgi?id=22053, https://lists.fedoraproject.org/archives/list/[email protected]/thread/RQDGCD7A4CTB5OSIWPDU522DPCUK6W6P/
Affected packages
Package
Name: perl-Catalyst-Plugin-Static-Simple
Purl: pkg:rpm/mageia/perl-Catalyst-Plugin-Static-Simple?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
