openSUSE Security Update : perl (openSUSE-SU-2010:0518-1)

High Nessus Plugin ID 48373

New! Vulnerability Priority Rating (VPR)

Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.

VPR Score: 6.7

Synopsis

The remote openSUSE host is missing a security update.

Description

perl Safe.pm module was affected by two problems where attackers could break out of such a safed execution. (CVE-2010-1447 , CVE-2010-1168)

This update fixes this problem. Also following non-security bugs were fixed :

- fix tell cornercase [bnc#596167]

- fix regex memory leak [bnc#557636]

- do not add vendorlib/auto to filelist [bnc#624628]

- also run h2ph on /usr/include/linux [bnc#603840]

- backport h2ph include fix from 5.12.0 [bnc#601242]

Solution

Update the affected perl packages.

See Also

https://bugzilla.novell.com/show_bug.cgi?id=557636

https://bugzilla.novell.com/show_bug.cgi?id=596167

https://bugzilla.novell.com/show_bug.cgi?id=601242

https://bugzilla.novell.com/show_bug.cgi?id=603840

https://bugzilla.novell.com/show_bug.cgi?id=605918

https://bugzilla.novell.com/show_bug.cgi?id=605928

https://bugzilla.novell.com/show_bug.cgi?id=624628

https://lists.opensuse.org/opensuse-updates/2010-08/msg00042.html

Plugin Details

Severity: High

ID: 48373

File Name: suse_11_2_perl-100730.nasl

Version: 1.7

Type: local

Agent: unix

Published: 2010/08/19

Updated: 2021/01/14

Dependencies: 12634

Risk Information

Risk Factor: High

VPR Score: 6.7

CVSS v2.0

Base Score: 8.5

Vector: CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:perl, p-cpe:/a:novell:opensuse:perl-32bit, p-cpe:/a:novell:opensuse:perl-base, p-cpe:/a:novell:opensuse:perl-base-32bit, cpe:/o:novell:opensuse:11.2

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 2010/07/30

Reference Information

CVE: CVE-2010-1168, CVE-2010-1447