- --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200212-6
- --------------------------------------------------------------------

PACKAGE : perl
SUMMARY : broken safe compartment
DATE    : 2002-12-20 14:12 UTC
EXPLOIT : local

- --------------------------------------------------------------------

Quote from   

"A security hole has been discovered in Safe.pm. When a Safe
compartment has already been used, there's no guarantee that it's safe
any longer, because there's a way for code executed within the Safe
compartment to alter its operation mask. (Thus, programs that use a
Safe compartment only once aren't affected by this bug"

Mor information is available at 
[perl #17744] Security-Hole in module Safe.pm

SOLUTION

It is recommended that all Gentoo Linux users who are running
sys-devel/perl-5.6.1-r9 or sys-devel/5.8.0-r5 and earlier update their
systems as follows:

emerge rsync
emerge perl
emerge clean

ALTERNATIVE SOLUTION

If you don't want to or can't upgrade your perl package right away,
you can emerge dev-perl/Safe to accomplish the same solution as above.

- --------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at mcummings@gentoo.org
- --------------------------------------------------------------------


Gentoo: perl broken safe compartment

A security hole has been discovered in Safe.pm

Summary


- --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200212-6
- --------------------------------------------------------------------
DATE    : 2002-12-20 14:12 UTC

- --------------------------------------------------------------------
Quote from
"A security hole has been discovered in Safe.pm. When a Safe compartment has already been used, there's no guarantee that it's safe any longer, because there's a way for code executed within the Safe compartment to alter its operation mask. (Thus, programs that use a Safe compartment only once aren't affected by this bug"
Mor information is available at [perl #17744] Security-Hole in module Safe.pm
SOLUTION
It is recommended that all Gentoo Linux users who are running sys-devel/perl-5.6.1-r9 or sys-devel/5.8.0-r5 and earlier update their systems as follows:
emerge rsync emerge perl emerge clean
ALTERNATIVE SOLUTION
If you don't want to or can't upgrade your perl package right away, y...

Read the Full Advisory

Resolution

References


Availability

Concerns


Severity
PACKAGE : perl
SUMMARY : broken safe compartment
EXPLOIT : local

Synopsis

Background

Affected Packages

Impact

Workaround

Related News