[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2586-1 perl -- several

ID: oval:org.secpod.oval:def:600926Date: (C)2012-12-14   (M)2023-12-07
Class: PATCHFamily: unix




Two vulnerabilities were discovered in the implementation of the Perl programming language: CVE-2012-5195 The "x" operator could cause the Perl interpreter to crash if very long strings were created. CVE-2012-5526 The CGI module does not properly escape LF characters in the Set-Cookie and P3P headers. In addition, this update adds a warning to the Storable documentation that this package is not suitable for deserializing untrusted data.

Platform:
Debian 6.0
Product:
perl
Reference:
DSA-2586-1
CVE-2012-5195
CVE-2012-5526
CVE    2
CVE-2012-5195
CVE-2012-5526
CPE    24
cpe:/a:perl:perl:5.12.1
cpe:/a:perl:perl:5.12.3:rc3
cpe:/a:perl:perl:5.12.0
cpe:/a:perl:perl:5.12.3:rc2
...

© SecPod Technologies