Skip to navigation

Security Advisory perl-DBI security update

Advisory: RHSA-2005:072-07
Type: Security Advisory
Severity: Low
Issued on: 2005-02-15
Last updated on: 2005-02-15
Affected Products: Red Hat Desktop (v. 4)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 4)
CVEs (cve.mitre.org): CVE-2005-0077

Details

An updated perl-DBI package that fixes a temporary file flaw in
DBI::ProxyServer is now available for Red Hat Enterprise Linux 4.

This update has been rated as having low security impact by the Red Hat
Security Response Team.

DBI is a database access Application Programming Interface (API) for
the Perl programming language.

The Debian Security Audit Project discovered that the DBI library creates a
temporary PID file in an insecure manner. A local user could overwrite or
create files as a different user who happens to run an application which
uses DBI::ProxyServer. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0077 to this issue.

Users should update to this erratum package which disables the temporary
PID file unless configured.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Updated packages

Red Hat Desktop (v. 4)

SRPMS:
perl-DBI-1.40-8.src.rpm
File outdated by:  RHBA-2008:0686
    MD5: 3f5f00c7f9484f6d1aa1eb2b5b0d2614
 
IA-32:
perl-DBI-1.40-8.i386.rpm
File outdated by:  RHBA-2008:0686
    MD5: 0407a8b42dc926caaa4cdbae2400b8be
 
x86_64:
perl-DBI-1.40-8.x86_64.rpm
File outdated by:  RHBA-2008:0686
    MD5: 81976ba94390dd25e69409de4cf4fcf0
 
Red Hat Enterprise Linux AS (v. 4)

SRPMS:
perl-DBI-1.40-8.src.rpm
File outdated by:  RHBA-2008:0686
    MD5: 3f5f00c7f9484f6d1aa1eb2b5b0d2614
 
IA-32:
perl-DBI-1.40-8.i386.rpm
File outdated by:  RHBA-2008:0686
    MD5: 0407a8b42dc926caaa4cdbae2400b8be
 
IA-64:
perl-DBI-1.40-8.ia64.rpm
File outdated by:  RHBA-2008:0686
    MD5: 2f1629ca7602562481639da97f5e009a
 
PPC:
perl-DBI-1.40-8.ppc.rpm
File outdated by:  RHBA-2008:0686
    MD5: a9a28fb845faf483e66253830c095cc9
 
s390:
perl-DBI-1.40-8.s390.rpm
File outdated by:  RHBA-2008:0686
    MD5: 1574b5f38084c6a0bde8a7c8c83ccb0c
 
s390x:
perl-DBI-1.40-8.s390x.rpm
File outdated by:  RHBA-2008:0686
    MD5: 04b4f82b9627867ce69f796512fa0fb8
 
x86_64:
perl-DBI-1.40-8.x86_64.rpm
File outdated by:  RHBA-2008:0686
    MD5: 81976ba94390dd25e69409de4cf4fcf0
 
Red Hat Enterprise Linux ES (v. 4)

SRPMS:
perl-DBI-1.40-8.src.rpm
File outdated by:  RHBA-2008:0686
    MD5: 3f5f00c7f9484f6d1aa1eb2b5b0d2614
 
IA-32:
perl-DBI-1.40-8.i386.rpm
File outdated by:  RHBA-2008:0686
    MD5: 0407a8b42dc926caaa4cdbae2400b8be
 
IA-64:
perl-DBI-1.40-8.ia64.rpm
File outdated by:  RHBA-2008:0686
    MD5: 2f1629ca7602562481639da97f5e009a
 
x86_64:
perl-DBI-1.40-8.x86_64.rpm
File outdated by:  RHBA-2008:0686
    MD5: 81976ba94390dd25e69409de4cf4fcf0
 
Red Hat Enterprise Linux WS (v. 4)

SRPMS:
perl-DBI-1.40-8.src.rpm
File outdated by:  RHBA-2008:0686
    MD5: 3f5f00c7f9484f6d1aa1eb2b5b0d2614
 
IA-32:
perl-DBI-1.40-8.i386.rpm
File outdated by:  RHBA-2008:0686
    MD5: 0407a8b42dc926caaa4cdbae2400b8be
 
IA-64:
perl-DBI-1.40-8.ia64.rpm
File outdated by:  RHBA-2008:0686
    MD5: 2f1629ca7602562481639da97f5e009a
 
x86_64:
perl-DBI-1.40-8.x86_64.rpm
File outdated by:  RHBA-2008:0686
    MD5: 81976ba94390dd25e69409de4cf4fcf0
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

145577 - CAN-2005-0077 perl-DBI insecure temporary file usage


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/