MGASA-2018-0428

    Dashboard / Vulnerabilities / MGASA-2018-0428

    MGASA-2018-0428

    Published: 3 Nov 2018Last Modified: 16 Apr 2026

    Summary: Updated perl-Dancer2 packages fix security vulnerabilities

    Details: Dancer2 0.206000 addresses several potential security issues. There is a potential RCE with regards to Storable. Dancer2 adds session ID validation to the session engine so that session backends based on Storable can reject malformed session IDs that may lead to exploitation of the RCE. Parsing requests now uses HTTP::Entity::Parser which reduces the amount of code needed and does not require re-parsing the request body. The perl-Dancer2 package has been updated to version 0.206.0 to fix this issue. Also, the perl-HTTP-XSCookies, perl-WWW-Form-UrlEncoded, perl-HTTP-MultiPartParser, and perl-HTTP-Entity-Parser dependencies have been added and the perl-Type-Tiny, perl-HTTP-Headers-Fast, perl-JSON-MaybeXS, perl-Cookie-Baker, and perl-Plack dependencies have been updated for the new perl-Dancer2 version.

    Affected packages

    Package

    Name: perl-Dancer2

    Purl: pkg:rpm/mageia/perl-Dancer2?arch=source&distro=mageia-6

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.206.0-1.1.mga6

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    MGASA-2018-0428 | CVE-DB