| Summary: | devel/p5-UI-Dialog: patch 1.09 for shell command execution bug (CVE-2008-7315) | ||
|---|---|---|---|
| Product: | Ports & Packages | Reporter: | Jason Unovitch <junovitch> |
| Component: | Individual Port(s) | Assignee: | freebsd-perl (Nobody) <perl> |
| Status: | Closed FIXED | ||
| Severity: | Affects Some People | Keywords: | security |
| Priority: | --- | Flags: | bugzilla:
maintainer-feedback?
(perl) |
| Version: | Latest | ||
| Hardware: | Any | ||
| OS: | Any | ||
|
Description
Jason Unovitch
2015-10-09 23:35:34 UTC
CPAN doesn't have the updated release yet despite the version bump on Github. Seems to be some very specific cases for using this for anything nefarious but we minds well and be safe and update to 1.11 as soon as it hits the mirrors. Committed patch from github. A commit references this bug: Author: mat Date: Sat Oct 10 07:09:20 UTC 2015 New revision: 398978 URL: https://svnweb.freebsd.org/changeset/ports/398978 Log: Apply upstream patch fixing CVE-2008-7315. PR: 203667 Obtained from: https://github.com/kckrinke/UI-Dialog/commit/6adc44cc636c615d76297d86835e1a997681eb61 Security: CVE-2008-7315 Sponsored by: Absolight Changes: head/devel/p5-UI-Dialog/Makefile head/devel/p5-UI-Dialog/files/ head/devel/p5-UI-Dialog/files/patch-6adc44cc636c615d76297d86835e1a997681eb61 A commit references this bug: Author: mat Date: Sat Oct 10 07:10:19 UTC 2015 New revision: 398979 URL: https://svnweb.freebsd.org/changeset/ports/398979 Log: MFH: r398978 Apply upstream patch fixing CVE-2008-7315. PR: 203667 Obtained from: https://github.com/kckrinke/UI-Dialog/commit/6adc44cc636c615d76297d86835e1a997681eb61 Security: CVE-2008-7315 Sponsored by: Absolight Changes: _U branches/2015Q4/ branches/2015Q4/devel/p5-UI-Dialog/Makefile branches/2015Q4/devel/p5-UI-Dialog/files/ A commit references this bug: Author: junovitch Date: Sat Oct 10 15:27:11 UTC 2015 New revision: 399004 URL: https://svnweb.freebsd.org/changeset/ports/399004 Log: Document shell command execution via improper escaping in p5-UI-Dialog PR: 203667 Security: CVE-2008-7315 Security: https://vuxml.FreeBSD.org/freebsd/00dadbf0-6f61-11e5-a2a1-002590263bf5.html Changes: head/security/vuxml/vuln.xml (In reply to Mathieu Arnold from comment #2) Thanks! Post close PR cleanup -- Fix title to reflect this isn't the "1.09 -> 1.11" update |