/[advisories]/14012.adv
ViewVC logotype

Contents of /14012.adv

Parent Directory Parent Directory | Revision Log Revision Log


Revision 3182 - (show annotations) (download)
Thu Jul 9 07:56:53 2015 UTC (8 years, 9 months ago) by tmb
File size: 646 byte(s)
fix up duplicated mitre cve links
1 type: security
2 subject: Updated perl-Plack package fixes security vulnerability
3 CVE:
4 - CVE-2014-5269
5 src:
6 3:
7 core:
8 - perl-Plack-1.1.400-2.1.mga3
9 4:
10 core:
11 - perl-Plack-1.2.900-2.1.mga4
12 description: |
13 Plack::App::File would previously strip trailing slashes off provided paths.
14 This in combination with the common pattern of serving files with
15 Plack::Middleware::Static could allow an attacker to bypass a whitelist of
16 generated files (CVE-2014-5269).
17 references:
18 - https://bugs.mageia.org/show_bug.cgi?id=14012
19 - https://lists.fedoraproject.org/pipermail/package-announce/2014-August/137115.html
20 ID: MGASA-2014-0486

  ViewVC Help
Powered by ViewVC 1.1.30