Open Source Development

Power Open Source Development

Explore the open source tools and capabilities for building and deploying modern applications on IBM Power platforms including AIX, IBM i, and Linux.


#Power


#Power

 View Only
  • 1.  PERL 5.28.0 Vulnerabilities

    Posted Tue December 18, 2018 03:39 PM

    Originally posted by: janhar


    Can you please provide status on the next build which will include fixes for the following CVEs:

     

    CVE-2018-12015  directory traversal in module Archive::Tar Vulnerability range: 5.8.0 - 5.26
                                  ** Previous forum update indicates this fix was included in perl-5.28.0-1.aix6.1.ppc.rpm on toolbox
    CVE-2018-18311  Integer overflow leading to buffer overflow: Vulnerability range: 5.8.0 - 5.28 (introduced in e658793210)
    CVE-2018-18312  Heap-buffer-overflow write / reg_node overrun: Vulnerability range: 5.18 - 5.28
    CVE-2018-18313  Heap-buffer-overflow read: Vulnerability range: 5.22 - 5.26 (introduced in b6d67071cc0)
    CVE-2018-18314  Heap-based buffer overflow: Vulnerability range: 5.18 - 5.28

     


    #AIXOpenSource
    #AIX-Open-Source-Software


  • 2.  Re: PERL 5.28.0 Vulnerabilities

    Posted Fri December 21, 2018 02:26 AM

    Originally posted by: AyappanP


    The current version 5.28.0 is affected by two CVEs mentioned here ( CVE-2018-18311 and CVE-2018-18312).

    We will shipping the new stable release 5.28.1 soon in AIX Toolbox.


    #AIXOpenSource
    #AIX-Open-Source-Software


  • 3.  Re: PERL 5.28.0 Vulnerabilities

    Posted Wed January 16, 2019 11:08 AM

    Originally posted by: Kristin M


    AyappanP,

    Is there an update on when the new stable release 5.28.1 may become available? Thank you.


    #AIX-Open-Source-Software
    #AIXOpenSource


  • 4.  Re: PERL 5.28.0 Vulnerabilities

    Posted Thu January 17, 2019 01:43 AM

    Originally posted by: AyappanP


    Before end of next week.

    The point to note here is this is for AIX Toolbox and not for the base lpp perl package. 


    #AIXOpenSource
    #AIX-Open-Source-Software


  • 5.  Re: PERL 5.28.0 Vulnerabilities

    Posted Mon January 28, 2019 09:13 AM

    Originally posted by: AyappanP


    Perl 5.28.1 is available now in AIX Toolbox. 

    ftp://public.dhe.ibm.com/aix/freeSoftware/aixtoolbox/RPMS/ppc/perl/

    One can also use yum to install it.


    #AIXOpenSource
    #AIX-Open-Source-Software