Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2021:0449-1

Опубликовано: 12 фев. 2021
Источник: suse-cvrf

Описание

Security update for perl-File-Path

This update for perl-File-Path fixes the following issues:

  • Provide File::Path version 2.15 to SLE-12-SP5 (jsc#SLE-17088, jsc#ECO-3050)
  • CVE-2017-6512: fix a race condition in the File-Path module for Perl.

Список пакетов

SUSE Linux Enterprise Server 12 SP5
perl-File-Path-2.150000-8.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
perl-File-Path-2.150000-8.3.1

Описание

Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:perl-File-Path-2.150000-8.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5:perl-File-Path-2.150000-8.3.1

Ссылки