openSUSE Security Update : perl (openSUSE-SU-2010:0519-1)

High Nessus Plugin ID 48372

New! Vulnerability Priority Rating (VPR)

Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.

VPR Score: 6.7

Synopsis

The remote openSUSE host is missing a security update.

Description

perl Safe.pm module was affected by two problems where attackers could break out of such a safed execution. (CVE-2010-1447 , CVE-2010-1168)

This update fixes this problem. Also the following bugs were fixed :

- fix tell cornercase [bnc#596167]

- fix regex memory leak [bnc#557636]

- also run h2ph on /usr/include/linux [bnc#603840]

- backport h2ph include fix from 5.12.0 [bnc#601242]

- fix segfault when using regexpes in threaded apps [bnc#588338]

- backport upstream fixes for POSIX module to avoid clashes with Fcntl [bnc#446098], [bnc#515948]

- backport upstream fix for ISA assertion failure [bnc#528423]

- move unicode files from perl-doc to perl, otherwise some perl modules will not work

Solution

Update the affected perl packages.

See Also

https://bugzilla.novell.com/show_bug.cgi?id=446098

https://bugzilla.novell.com/show_bug.cgi?id=515948

https://bugzilla.novell.com/show_bug.cgi?id=528423

https://bugzilla.novell.com/show_bug.cgi?id=557636

https://bugzilla.novell.com/show_bug.cgi?id=588338

https://bugzilla.novell.com/show_bug.cgi?id=596167

https://bugzilla.novell.com/show_bug.cgi?id=601242

https://bugzilla.novell.com/show_bug.cgi?id=603840

https://bugzilla.novell.com/show_bug.cgi?id=605918

https://bugzilla.novell.com/show_bug.cgi?id=605928

https://lists.opensuse.org/opensuse-updates/2010-08/msg00043.html

Plugin Details

Severity: High

ID: 48372

File Name: suse_11_1_perl-100730.nasl

Version: 1.7

Type: local

Agent: unix

Published: 2010/08/19

Updated: 2021/01/14

Dependencies: 12634

Risk Information

Risk Factor: High

VPR Score: 6.7

CVSS v2.0

Base Score: 8.5

Vector: CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:perl, p-cpe:/a:novell:opensuse:perl-32bit, p-cpe:/a:novell:opensuse:perl-base, p-cpe:/a:novell:opensuse:perl-base-32bit, cpe:/o:novell:opensuse:11.1

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 2010/07/30

Reference Information

CVE: CVE-2010-1168, CVE-2010-1447