Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
libemail-address-perl | fixed | 1.908-1 | package | |
libemail-address-perl | ignored | jessie | package | |
libemail-address-perl | ignored | wheezy | package | |
libemail-address-perl | fixed | 1.889-2+deb6u2 | squeeze | package |
Примечания
workaround entry for DLA-320-1 until/if CVE assigned
For the denial of service issue as of 1.908 as mitigation default value
for nestable comments set to deep level 1.
https://github.com/rjbs/Email-Address/commit/3056b7da4fffbce9ad92f9799fffc587ab40303d
No CVE will be assigned for behaviour change between 1.907 and 1.908
See CVE-2015-7686 for the underlying CWE-407 ("Algorithmic Complexity")
issue still present in 1.908
https://www.openwall.com/lists/oss-security/2015/10/02/13