Skip to navigation

Security Advisory perl security update

Advisory: RHSA-2005:674-10
Type: Security Advisory
Severity: Low
Issued on: 2005-10-05
Last updated on: 2005-10-05
Affected Products: Red Hat Desktop (v. 4)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 4)
CVEs (cve.mitre.org): CVE-2005-0448

Details

Updated Perl packages that fix security issues and contain several bug
fixes are now available for Red Hat Enterprise Linux 4.

This update has been rated as having low security impact by the Red Hat
Security Response Team.

Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

Paul Szabo discovered a bug in the way Perl's File::Path::rmtree module
removed directory trees. If a local user has write permissions to a
subdirectory within the tree being removed by File::Path::rmtree, it is
possible for them to create setuid binary files. The Common Vulnerabilities
and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0448
to this issue.

This update also addresses the following issues:

-- Perl interpreter caused a segmentation fault when environment
changes occurred during runtime.

-- Code in lib/FindBin contained a regression that caused problems with
MRTG software package.

-- Perl incorrectly declared it provides an FCGI interface where it in fact
did not.

Users of Perl are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Updated packages

Red Hat Desktop (v. 4)

SRPMS:
perl-5.8.5-16.RHEL4.src.rpm
File outdated by:  RHSA-2011:1797
    MD5: 680ce92a9da6cccf344e1b13123d9aaa
 
IA-32:
perl-5.8.5-16.RHEL4.i386.rpm
File outdated by:  RHSA-2011:1797
    MD5: 9ec1570c81d4034b22e5b4e10d1b9e18
perl-suidperl-5.8.5-16.RHEL4.i386.rpm
File outdated by:  RHSA-2011:1797
    MD5: cfe9e85adc4c8faa977e56f3ff06abd3
 
x86_64:
perl-5.8.5-16.RHEL4.x86_64.rpm
File outdated by:  RHSA-2011:1797
    MD5: 0d14d35ee0f24120c7e3e36e17ee3ea1
perl-suidperl-5.8.5-16.RHEL4.x86_64.rpm
File outdated by:  RHSA-2011:1797
    MD5: 41c3d79fba9d74c3e7da6f57d4d167ee
 
Red Hat Enterprise Linux AS (v. 4)

SRPMS:
perl-5.8.5-16.RHEL4.src.rpm
File outdated by:  RHSA-2011:1797
    MD5: 680ce92a9da6cccf344e1b13123d9aaa
 
IA-32:
perl-5.8.5-16.RHEL4.i386.rpm
File outdated by:  RHSA-2011:1797
    MD5: 9ec1570c81d4034b22e5b4e10d1b9e18
perl-suidperl-5.8.5-16.RHEL4.i386.rpm
File outdated by:  RHSA-2011:1797
    MD5: cfe9e85adc4c8faa977e56f3ff06abd3
 
IA-64:
perl-5.8.5-16.RHEL4.ia64.rpm
File outdated by:  RHSA-2011:1797
    MD5: 453283cb6c5d392580a318ddf0a5fbb5
perl-suidperl-5.8.5-16.RHEL4.ia64.rpm
File outdated by:  RHSA-2011:1797
    MD5: 9f01a4ef79fc601ac34892d5df64a7a4
 
PPC:
perl-5.8.5-16.RHEL4.ppc.rpm
File outdated by:  RHSA-2011:1797
    MD5: 89dad8dbc4dc1ca219ad353c0ebce105
perl-suidperl-5.8.5-16.RHEL4.ppc.rpm
File outdated by:  RHSA-2011:1797
    MD5: d768e18d710ed0ddf9ff928cd7b62991
 
s390:
perl-5.8.5-16.RHEL4.s390.rpm
File outdated by:  RHSA-2011:1797
    MD5: d2b9782e99e123ada2a42c0719d4286b
perl-suidperl-5.8.5-16.RHEL4.s390.rpm
File outdated by:  RHSA-2011:1797
    MD5: 786148799901a80afa9ae8ecd8a08c88
 
s390x:
perl-5.8.5-16.RHEL4.s390x.rpm
File outdated by:  RHSA-2011:1797
    MD5: d2a24c5fbc21634c1242477a1f959df8
perl-suidperl-5.8.5-16.RHEL4.s390x.rpm
File outdated by:  RHSA-2011:1797
    MD5: ef1e3ff9dfeb8bb39807841fdabbc3c9
 
x86_64:
perl-5.8.5-16.RHEL4.x86_64.rpm
File outdated by:  RHSA-2011:1797
    MD5: 0d14d35ee0f24120c7e3e36e17ee3ea1
perl-suidperl-5.8.5-16.RHEL4.x86_64.rpm
File outdated by:  RHSA-2011:1797
    MD5: 41c3d79fba9d74c3e7da6f57d4d167ee
 
Red Hat Enterprise Linux ES (v. 4)

SRPMS:
perl-5.8.5-16.RHEL4.src.rpm
File outdated by:  RHSA-2011:1797
    MD5: 680ce92a9da6cccf344e1b13123d9aaa
 
IA-32:
perl-5.8.5-16.RHEL4.i386.rpm
File outdated by:  RHSA-2011:1797
    MD5: 9ec1570c81d4034b22e5b4e10d1b9e18
perl-suidperl-5.8.5-16.RHEL4.i386.rpm
File outdated by:  RHSA-2011:1797
    MD5: cfe9e85adc4c8faa977e56f3ff06abd3
 
IA-64:
perl-5.8.5-16.RHEL4.ia64.rpm
File outdated by:  RHSA-2011:1797
    MD5: 453283cb6c5d392580a318ddf0a5fbb5
perl-suidperl-5.8.5-16.RHEL4.ia64.rpm
File outdated by:  RHSA-2011:1797
    MD5: 9f01a4ef79fc601ac34892d5df64a7a4
 
x86_64:
perl-5.8.5-16.RHEL4.x86_64.rpm
File outdated by:  RHSA-2011:1797
    MD5: 0d14d35ee0f24120c7e3e36e17ee3ea1
perl-suidperl-5.8.5-16.RHEL4.x86_64.rpm
File outdated by:  RHSA-2011:1797
    MD5: 41c3d79fba9d74c3e7da6f57d4d167ee
 
Red Hat Enterprise Linux WS (v. 4)

SRPMS:
perl-5.8.5-16.RHEL4.src.rpm
File outdated by:  RHSA-2011:1797
    MD5: 680ce92a9da6cccf344e1b13123d9aaa
 
IA-32:
perl-5.8.5-16.RHEL4.i386.rpm
File outdated by:  RHSA-2011:1797
    MD5: 9ec1570c81d4034b22e5b4e10d1b9e18
perl-suidperl-5.8.5-16.RHEL4.i386.rpm
File outdated by:  RHSA-2011:1797
    MD5: cfe9e85adc4c8faa977e56f3ff06abd3
 
IA-64:
perl-5.8.5-16.RHEL4.ia64.rpm
File outdated by:  RHSA-2011:1797
    MD5: 453283cb6c5d392580a318ddf0a5fbb5
perl-suidperl-5.8.5-16.RHEL4.ia64.rpm
File outdated by:  RHSA-2011:1797
    MD5: 9f01a4ef79fc601ac34892d5df64a7a4
 
x86_64:
perl-5.8.5-16.RHEL4.x86_64.rpm
File outdated by:  RHSA-2011:1797
    MD5: 0d14d35ee0f24120c7e3e36e17ee3ea1
perl-suidperl-5.8.5-16.RHEL4.x86_64.rpm
File outdated by:  RHSA-2011:1797
    MD5: 41c3d79fba9d74c3e7da6f57d4d167ee
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

127023 - perl fails "lib/FindBin" test (breaks MRTG)
148848 - Packing fault with perl and FCGI
155888 - perl-suidperl package has an extra .1 release suffix
157694 - CAN-2005-0448 perl File::Path.pm rmtree race condition


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/