Säkerhetsbulletin från Debian
DSA-620-1 perl -- osäkra temporära filer och kataloger
- Rapporterat den:
- 2004-12-30
- Berörda paket:
- perl
- Sårbara:
- Ja
- Referenser i säkerhetsdatabaser:
- I Mitres CVE-förteckning: CVE-2004-0452, CVE-2004-0976.
- Ytterligare information:
-
Flera sårbarheter har upptäckts i Perl, det populära skriptspråket. Projektet Common Vulnerabilities and Exposures identifierar följande problem:
- CAN-2004-0452
Jeroen van Wolffelaar upptäckte att funktionen rmtree() i modulen File::Path tar bort katalogträd på ett osäkert sätt, något som kunde leda till att en angripare kunde ta bort godtyckliga filer och kataloger genom att angripa symboliska länkar.
- CAN-2004-0976
Utvecklare på Trustix upptäckte flera moduler där temporära filer användes på ett osäkert sätt, vilket kunde låta en lokal angripare att skriva över filer genom att angripa symboliska länkar.
För den stabila utgåvan (Woody) har dessa problem rättats i version 5.6.1-8.8.
För den instabila utgåvan (Sid) har dessa problem rättats i version 5.8.4-5.
Vi rekommenderar att ni uppgraderar era perl-paket.
- CAN-2004-0452
- Rättat i:
-
Debian GNU/Linux 3.0 (woody)
- Källkod:
- http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8.dsc
- http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8.diff.gz
- http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1.orig.tar.gz
- http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8.diff.gz
- Arkitekturoberoende komponent:
- http://security.debian.org/pool/updates/main/p/perl/libcgi-fast-perl_5.6.1-8.8_all.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-doc_5.6.1-8.8_all.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-modules_5.6.1-8.8_all.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-doc_5.6.1-8.8_all.deb
- Alpha:
- http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_alpha.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_alpha.deb
- http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_alpha.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_alpha.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_alpha.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_alpha.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_alpha.deb
- ARM:
- http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_arm.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_arm.deb
- http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_arm.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_arm.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_arm.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_arm.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_arm.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_i386.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_i386.deb
- http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_i386.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_i386.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_i386.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_i386.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_i386.deb
- Intel IA-64:
- http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_ia64.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_ia64.deb
- http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_ia64.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_ia64.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_ia64.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_ia64.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_ia64.deb
- HPPA:
- http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_hppa.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_hppa.deb
- http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_hppa.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_hppa.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_hppa.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_hppa.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_hppa.deb
- Motorola 680x0:
- http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_m68k.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_m68k.deb
- http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_m68k.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_m68k.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_m68k.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_m68k.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_m68k.deb
- Big endian MIPS:
- http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_mips.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_mips.deb
- http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_mips.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_mips.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_mips.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_mips.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_mips.deb
- Little endian MIPS:
- http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_mipsel.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_mipsel.deb
- http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_mipsel.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_mipsel.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_mipsel.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_mipsel.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_mipsel.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_powerpc.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_powerpc.deb
- http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_powerpc.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_powerpc.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_powerpc.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_powerpc.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_powerpc.deb
- IBM S/390:
- http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_s390.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_s390.deb
- http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_s390.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_s390.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_s390.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_s390.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_s390.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_sparc.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_sparc.deb
- http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_sparc.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_sparc.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_sparc.deb
- http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_sparc.deb
- http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_sparc.deb
MD5-kontrollsummor för dessa filer finns i originalbulletinen.