AIX Open Source

AIX Open Source

Share your experiences and connect with fellow developers to discover how to build and manage open source software for the AIX operating system

 View Only
  • 1.  PERL 5.28.0 Vulnerabilities

    Posted Tue December 18, 2018 03:39 PM

    Originally posted by: janhar


    Can you please provide status on the next build which will include fixes for the following CVEs:

     

    CVE-2018-12015  directory traversal in module Archive::Tar Vulnerability range: 5.8.0 - 5.26
                                  ** Previous forum update indicates this fix was included in perl-5.28.0-1.aix6.1.ppc.rpm on toolbox
    CVE-2018-18311  Integer overflow leading to buffer overflow: Vulnerability range: 5.8.0 - 5.28 (introduced in e658793210)
    CVE-2018-18312  Heap-buffer-overflow write / reg_node overrun: Vulnerability range: 5.18 - 5.28
    CVE-2018-18313  Heap-buffer-overflow read: Vulnerability range: 5.22 - 5.26 (introduced in b6d67071cc0)
    CVE-2018-18314  Heap-based buffer overflow: Vulnerability range: 5.18 - 5.28

     



  • 2.  Re: PERL 5.28.0 Vulnerabilities

    Posted Fri December 21, 2018 02:26 AM

    Originally posted by: AyappanP


    The current version 5.28.0 is affected by two CVEs mentioned here ( CVE-2018-18311 and CVE-2018-18312).

    We will shipping the new stable release 5.28.1 soon in AIX Toolbox.



  • 3.  Re: PERL 5.28.0 Vulnerabilities

    Posted Wed January 16, 2019 11:08 AM

    Originally posted by: Kristin M


    AyappanP,

    Is there an update on when the new stable release 5.28.1 may become available? Thank you.



  • 4.  Re: PERL 5.28.0 Vulnerabilities

    Posted Thu January 17, 2019 01:43 AM

    Originally posted by: AyappanP


    Before end of next week.

    The point to note here is this is for AIX Toolbox and not for the base lpp perl package. 



  • 5.  Re: PERL 5.28.0 Vulnerabilities

    Posted Mon January 28, 2019 09:13 AM

    Originally posted by: AyappanP


    Perl 5.28.1 is available now in AIX Toolbox. 

    ftp://public.dhe.ibm.com/aix/freeSoftware/aixtoolbox/RPMS/ppc/perl/

    One can also use yum to install it.