SUSE-SU-2017:3092-1
Dashboard / Vulnerabilities / SUSE-SU-2017:3092-1
SUSE-SU-2017:3092-1
Summary: Security update for perl
Details: This update for perl fixes the following issues: Security issues fixed: - CVE-2017-12837: Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\N{}' escape and the case-insensitive modifier. (bnc#1057724) - CVE-2017-12883: Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of service (application crash) via a crafted regular expression with an invalid '\N{U+...}' escape. (bnc#1057721) - CVE-2017-6512: Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic. (bnc#1047178) Bug fixes: - backport set_capture_string changes from upstream (bsc#999735) - reformat baselibs.conf as source validator workaround
References: https://www.suse.com/support/update/announcement/2017/suse-su-20173092-1/, https://bugzilla.suse.com/1047178, https://bugzilla.suse.com/1057721, https://bugzilla.suse.com/1057724, https://bugzilla.suse.com/999735, https://www.suse.com/security/cve/CVE-2017-12837, https://www.suse.com/security/cve/CVE-2017-12883, https://www.suse.com/security/cve/CVE-2017-6512
Affected packages
Package
Name: perl
Purl: pkg:rpm/suse/perl&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
