int(3560)

Boletines de Vulnerabilidades


Ejecución de código arbitrario en el motor de expresiones regulares de Perl

Clasificación de la vulnerabilidad

Propiedad Valor
Nivel de Confianza Oficial
Impacto Obtener acceso
Dificultad Experto
Requerimientos del atacante Acceso remoto sin cuenta a un servicio estandar

Información sobre el sistema

Propiedad Valor
Fabricante afectado GNU/Linux
Software afectado Perl

Descripción

Se ha encontrado una vulnerabilidad en Perl. La vulnerabilidad reside en un error en el motor de expresiones regulares.

Un atacante remoto podría ejecutar código arbitrario con los permisos del usuario que ejecuta Perl mediante una expresión regular especialmente diseñada que provoca un direccionamiento de memoria incorrecto.

Solución



Actualización de software

Mandriva (MDKSA-2007:207)

Corporate Server 3.0
X86
corporate/3.0/i586/perl-5.8.3-5.6.C30mdk.i586.rpm
corporate/3.0/i586/perl-base-5.8.3-5.6.C30mdk.i586.rpm
corporate/3.0/i586/perl-devel-5.8.3-5.6.C30mdk.i586.rpm
corporate/3.0/i586/perl-doc-5.8.3-5.6.C30mdk.i586.rpm
corporate/3.0/SRPMS/perl-5.8.3-5.6.C30mdk.src.rpm
X86_64
corporate/3.0/x86_64/perl-5.8.3-5.6.C30mdk.x86_64.rpm
corporate/3.0/x86_64/perl-base-5.8.3-5.6.C30mdk.x86_64.rpm
corporate/3.0/x86_64/perl-devel-5.8.3-5.6.C30mdk.x86_64.rpm
corporate/3.0/x86_64/perl-doc-5.8.3-5.6.C30mdk.x86_64.rpm
corporate/3.0/SRPMS/perl-5.8.3-5.6.C30mdk.src.rpm

Multi Network Firewall 2.0
X86
mnf/2.0/i586/perl-5.8.3-5.6.M20mdk.i586.rpm
mnf/2.0/i586/perl-base-5.8.3-5.6.M20mdk.i586.rpm
mnf/2.0/i586/perl-devel-5.8.3-5.6.M20mdk.i586.rpm
mnf/2.0/i586/perl-doc-5.8.3-5.6.M20mdk.i586.rpm
mnf/2.0/SRPMS/perl-5.8.3-5.6.M20mdk.src.rpm

Mandriva Linux 2007
X86
2007.0/i586/perl-5.8.8-7.1mdv2007.0.i586.rpm
2007.0/i586/perl-base-5.8.8-7.1mdv2007.0.i586.rpm
2007.0/i586/perl-devel-5.8.8-7.1mdv2007.0.i586.rpm
2007.0/i586/perl-doc-5.8.8-7.1mdv2007.0.i586.rpm
2007.0/i586/perl-suid-5.8.8-7.1mdv2007.0.i586.rpm
2007.0/SRPMS/perl-5.8.8-7.1mdv2007.0.src.rpm
X86_64
2007.0/x86_64/perl-5.8.8-7.1mdv2007.0.x86_64.rpm
2007.0/x86_64/perl-base-5.8.8-7.1mdv2007.0.x86_64.rpm
2007.0/x86_64/perl-devel-5.8.8-7.1mdv2007.0.x86_64.rpm
2007.0/x86_64/perl-doc-5.8.8-7.1mdv2007.0.x86_64.rpm
2007.0/x86_64/perl-suid-5.8.8-7.1mdv2007.0.x86_64.rpm
2007.0/SRPMS/perl-5.8.8-7.1mdv2007.0.src.rpm

Corporate Server 4.0
X86
corporate/4.0/i586/perl-5.8.7-3.3.20060mlcs4.i586.rpm
corporate/4.0/i586/perl-base-5.8.7-3.3.20060mlcs4.i586.rpm
corporate/4.0/i586/perl-devel-5.8.7-3.3.20060mlcs4.i586.rpm
corporate/4.0/i586/perl-doc-5.8.7-3.3.20060mlcs4.i586.rpm
corporate/4.0/i586/perl-suid-5.8.7-3.3.20060mlcs4.i586.rpm
corporate/4.0/SRPMS/perl-5.8.7-3.3.20060mlcs4.src.rpm
X86_64
corporate/4.0/x86_64/perl-5.8.7-3.3.20060mlcs4.x86_64.rpm
corporate/4.0/x86_64/perl-base-5.8.7-3.3.20060mlcs4.x86_64.rpm
corporate/4.0/x86_64/perl-devel-5.8.7-3.3.20060mlcs4.x86_64.rpm
corporate/4.0/x86_64/perl-doc-5.8.7-3.3.20060mlcs4.x86_64.rpm
corporate/4.0/x86_64/perl-suid-5.8.7-3.3.20060mlcs4.x86_64.rpm
corporate/4.0/SRPMS/perl-5.8.7-3.3.20060mlcs4.src.rpm

Mandriva Linux 2007.1
X86
2007.1/i586/perl-5.8.8-10.1mdv2007.1.i586.rpm
2007.1/i586/perl-base-5.8.8-10.1mdv2007.1.i586.rpm
2007.1/i586/perl-devel-5.8.8-10.1mdv2007.1.i586.rpm
2007.1/i586/perl-doc-5.8.8-10.1mdv2007.1.i586.rpm
2007.1/i586/perl-suid-5.8.8-10.1mdv2007.1.i586.rpm
2007.1/SRPMS/perl-5.8.8-10.1mdv2007.1.src.rpm
X86_64
2007.1/x86_64/perl-5.8.8-10.1mdv2007.1.x86_64.rpm
2007.1/x86_64/perl-base-5.8.8-10.1mdv2007.1.x86_64.rpm
2007.1/x86_64/perl-devel-5.8.8-10.1mdv2007.1.x86_64.rpm
2007.1/x86_64/perl-doc-5.8.8-10.1mdv2007.1.x86_64.rpm
2007.1/x86_64/perl-suid-5.8.8-10.1mdv2007.1.x86_64.rpm
2007.1/SRPMS/perl-5.8.8-10.1mdv2007.1.src.rpm

Mandriva Linux 2008.0
X86
2008.0/i586/perl-5.8.8-12.1mdv2008.0.i586.rpm
2008.0/i586/perl-base-5.8.8-12.1mdv2008.0.i586.rpm
2008.0/i586/perl-devel-5.8.8-12.1mdv2008.0.i586.rpm
2008.0/i586/perl-doc-5.8.8-12.1mdv2008.0.i586.rpm
2008.0/i586/perl-suid-5.8.8-12.1mdv2008.0.i586.rpm
2008.0/SRPMS/perl-5.8.8-12.1mdv2008.0.src.rpm
X86_64
2008.0/x86_64/perl-5.8.8-12.1mdv2008.0.x86_64.rpm
2008.0/x86_64/perl-base-5.8.8-12.1mdv2008.0.x86_64.rpm
2008.0/x86_64/perl-devel-5.8.8-12.1mdv2008.0.x86_64.rpm
2008.0/x86_64/perl-doc-5.8.8-12.1mdv2008.0.x86_64.rpm
2008.0/x86_64/perl-suid-5.8.8-12.1mdv2008.0.x86_64.rpm
2008.0/SRPMS/perl-5.8.8-12.1mdv2008.0.src.rpm

Red Hat (RHSA-2007:0966-5)
Red Hat Desktop (v. 3)
Red Hat Desktop (v. 4)
Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux Desktop (v. 5 client)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 3)
Red Hat Enterprise Linux WS (v. 4)
https://rhn.redhat.com/

Debian (DSA 1400-1)

Debian Linux 3.1
Source
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.4-8sarge6.dsc
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.4-8sarge6.diff.gz
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.4.orig.tar.gz
Architecture independent
http://security.debian.org/pool/updates/main/p/perl/libcgi-fast-perl_5.8.4-8sarge6_all.deb
http://security.debian.org/pool/updates/main/p/perl/perl-doc_5.8.4-8sarge6_all.deb
http://security.debian.org/pool/updates/main/p/perl/perl-modules_5.8.4-8sarge6_all.deb
Alpha
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.4-8sarge6_alpha.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.4-8sarge6_alpha.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.4-8sarge6_alpha.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.4-8sarge6_alpha.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.4-8sarge6_alpha.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.4-8sarge6_alpha.deb
AMD64
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.4-8sarge6_amd64.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.4-8sarge6_amd64.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.4-8sarge6_amd64.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.4-8sarge6_amd64.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.4-8sarge6_amd64.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.4-8sarge6_amd64.deb
ARM
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.4-8sarge3_arm.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.4-8sarge3_arm.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.4-8sarge3_arm.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.4-8sarge3_arm.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.4-8sarge3_arm.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.4-8sarge3_arm.deb
HP Precision
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.4-8sarge6_hppa.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.4-8sarge6_hppa.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.4-8sarge6_hppa.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.4-8sarge6_hppa.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.4-8sarge6_hppa.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.4-8sarge6_hppa.deb
Intel IA-32
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.4-8sarge6_i386.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.4-8sarge6_i386.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.4-8sarge6_i386.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.4-8sarge6_i386.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.4-8sarge6_i386.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.4-8sarge6_i386.deb
Intel IA-64
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.4-8sarge6_ia64.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.4-8sarge6_ia64.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.4-8sarge6_ia64.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.4-8sarge6_ia64.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.4-8sarge6_ia64.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.4-8sarge6_ia64.deb
Motorola 680x0
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.4-8sarge3_m68k.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.4-8sarge3_m68k.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.4-8sarge3_m68k.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.4-8sarge3_m68k.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.4-8sarge3_m68k.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.4-8sarge3_m68k.deb
Big endian MIPS
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.4-8sarge3_mips.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.4-8sarge3_mips.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.4-8sarge3_mips.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.4-8sarge3_mips.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.4-8sarge3_mips.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.4-8sarge3_mips.deb
Little endian MIPS
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.4-8sarge6_mipsel.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.4-8sarge6_mipsel.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.4-8sarge6_mipsel.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.4-8sarge6_mipsel.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.4-8sarge6_mipsel.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.4-8sarge6_mipsel.deb
PowerPC
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.4-8sarge6_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.4-8sarge6_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.4-8sarge6_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.4-8sarge6_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.4-8sarge6_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.4-8sarge6_powerpc.deb
IBM S/390
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.4-8sarge6_s390.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.4-8sarge6_s390.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.4-8sarge6_s390.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.4-8sarge6_s390.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.4-8sarge6_s390.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.4-8sarge6_s390.deb
Sun Sparc
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.4-8sarge6_sparc.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.4-8sarge6_sparc.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.4-8sarge6_sparc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.4-8sarge6_sparc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.4-8sarge6_sparc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.4-8sarge6_sparc.deb

Debian Linux 4.0
Source
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch1.dsc
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch1.diff.gz
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8.orig.tar.gz
Architecture independent
http://security.debian.org/pool/updates/main/p/perl/libcgi-fast-perl_5.8.8-7etch1_all.deb
http://security.debian.org/pool/updates/main/p/perl/perl-doc_5.8.8-7etch1_all.deb
http://security.debian.org/pool/updates/main/p/perl/perl-modules_5.8.8-7etch1_all.deb
Alpha
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch1_alpha.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch1_alpha.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch1_alpha.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch1_alpha.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch1_alpha.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch1_alpha.deb
AMD64
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch1_amd64.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch1_amd64.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch1_amd64.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch1_amd64.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch1_amd64.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch1_amd64.deb
ARM
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch1_arm.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch1_arm.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch1_arm.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch1_arm.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch1_arm.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch1_arm.deb
HP Precision
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch1_hppa.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch1_hppa.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch1_hppa.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch1_hppa.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch1_hppa.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch1_hppa.deb
Intel IA-32
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch1_i386.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch1_i386.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch1_i386.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch1_i386.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch1_i386.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch1_i386.deb
Intel IA-64
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch1_ia64.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch1_ia64.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch1_ia64.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch1_ia64.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch1_ia64.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch1_ia64.deb
Little endian MIPS
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch1_mipsel.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch1_mipsel.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch1_mipsel.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch1_mipsel.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch1_mipsel.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch1_mipsel.deb
PowerPC
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch1_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch1_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch1_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch1_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch1_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch1_powerpc.deb
Sun Sparc
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.8.8-7etch1_sparc.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.8_5.8.8-7etch1_sparc.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.8.8-7etch1_sparc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.8.8-7etch1_sparc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.8.8-7etch1_sparc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.8.8-7etch1_sparc.deb

Suse Linux
Las actualizaciones pueden descargarse mediante YAST o del servidor FTP oficial de Suse Linux.

Apple
Security Update 2007-009 / Mac OS X 10.4.11 (Universal)
http://www.apple.com/support/downloads/securityupdate200700910411universal.html
Security Update 2007-009 / Max OS X 10.4.11 (PPC)
http://www.apple.com/support/downloads/securityupdate200700910411ppc.html
Security Update 2007-009 / Max OS X 10.5.1
http://www.apple.com/support/downloads/securityupdate20070091051.html



Actualización de software

IBM
AIX 5.2 - APAR IZ10220 (Disponible el 14/05/2008)
http://www.ibm.com/support/docview.wss?uid=isg1IZ10220
AIX 5.3 hasta TL06 - APAR IZ10244
http://www.ibm.com/support/docview.wss?uid=isg1IZ10244
AIX 5.3 TL07 - APAR IZ10245
AIX 6.1.0 - APAR IZ10245
http://www.ibm.com/servers/eserver/support/unixservers/aixfixes.html

Hewlett-Packard
HP Tru64 UNIX Version v5.1B-4 PK6 (BL27) / Early Release Patch perl_V51BB27-ES-20080207
http://www.itrc.hp.com/service/patch/patchDetail.do?patchid=perl_V51BB27-ES-20080207
HP Tru64 UNIX Version v5.1B-3 PK5 (BL26) / Early Release Patch perl_V51BB26-ES-20080204
http://www.itrc.hp.com/service/patch/patchDetail.do?patchid=T64KIT1001399-V51BB26-ES-20071207
Internet Express (IX) for HP Tru64 UNIX v 6.7 / Utilice uno de los parches anteriores para su versión de sistema operativo.

Sun (231524)
Solaris 10 / SPARC / patch 122239-03 o posterior
Solaris 10 / x86 / patch 122240-03 o posterior
http://sunsolve.sun.com/pub-cgi/show.pl?target=patchpage

Identificadores estándar

Propiedad Valor
CVE CVE-2007-5116
BID

Recursos adicionales

Mandriva Security Advisory (MDKSA-2007:207)
http://www.mandriva.com/security/advisories?name=MDKSA-2007:207

Red Hat Security Advisory (RHSA-2007:0966-5)
https://rhn.redhat.com/errata/RHSA-2007-0966.html

Debian Security Advisory (DSA 1400-1)
http://lists.debian.org/debian-security-announce/debian-security-announce-2007/msg00179.html

SUSE Security Summary Report (SUSE-SR:2007:024)
http://www.novell.com/linux/security/advisories/2007_24_sr.html

Apple Security Update (307179)
http://docs.info.apple.com/article.html?artnum=307179

IBM Security Advisory (4047)
https://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoe?mode=7&heading=AIX61&path=%2F200712%2FSECURITY%2F20071218%2Fdatafile114034&label=AIX+Perl+buffer+overflow+vulnerability

HP SECURITY BULLETIN (HPSBTU02311)
https://www12.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01362465-1

Sun Alert Notification (231524)
http://sunsolve.sun.com/search/document.do?assetkey=1-66-231524-1

Histórico de versiones

Versión Comentario Fecha
1.0 Aviso emitido 2007-11-07
1.1 Aviso emitido por Debian (DSA 1400-1) 2007-11-08
1.2 Aviso emitido por Suse (SUSE-SR:2007:024) 2007-11-26
1.3 Aviso emitido por Apple (307179), aviso emitido por IBM (4047) 2007-12-28
1.4 Aviso emitido por HP (HPSBTU02311) 2008-02-21
1.5 Aviso actualizado por IBM 2008-03-12
1.6 Aviso emitido por Sun (231524) 2008-08-19

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT