Boletines de Vulnerabilidades |
Múltiples vulnerabilidades en perl |
|
Clasificación de la vulnerabilidad |
|
Propiedad | Valor |
Nivel de Confianza | Oficial |
Impacto | Integridad |
Dificultad | Avanzado |
Requerimientos del atacante | Acceso remoto con cuenta |
Información sobre el sistema |
|
Propiedad | Valor |
Fabricante afectado | GNU/Linux |
Software afectado |
Perl 5.6.1 Perl 5.8.4 |
Descripción |
|
Se han encontrado varias vulnerabilidades en Perl: CAN-2004-0452 - Existe una vulnerabilidad en la función rmtree(), de tal forma que se borran árboles de directorios de forma insegura; ello podría permitir a un atacante borrar archivos arbitrarios mediante un ataque de enlace simbólico. CAN-2004-0976 - Se han encontrado diferentes usos no seguros de archivos temporales en algunos módulos, lo cual podría permitir a un atacante local sobreescribir archivos mediante un ataque de enlace simbólico. |
|
Solución |
|
Actualización de software Debian Linux Debian Linux 3.0 Source: http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8.dsc http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8.diff.gz http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1.orig.tar.gz Architecture-independent component: http://security.debian.org/pool/updates/main/p/perl/libcgi-fast-perl_5.6.1-8.8_all.deb http://security.debian.org/pool/updates/main/p/perl/perl-doc_5.6.1-8.8_all.deb http://security.debian.org/pool/updates/main/p/perl/perl-modules_5.6.1-8.8_all.deb Alpha: http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_alpha.deb http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_alpha.deb http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_alpha.deb http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_alpha.deb http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_alpha.deb http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_alpha.deb ARM: http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_arm.deb http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_arm.deb http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_arm.deb http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_arm.deb http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_arm.deb http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_arm.deb Intel IA-32: http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_i386.deb http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_i386.deb http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_i386.deb http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_i386.deb http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_i386.deb http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_i386.deb Intel IA-64: http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_ia64.deb http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_ia64.deb http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_ia64.deb http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_ia64.deb http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_ia64.deb http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_ia64.deb HPPA: http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_hppa.deb http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_hppa.deb http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_hppa.deb http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_hppa.deb http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_hppa.deb http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_hppa.deb Motorola 680x0: http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_m68k.deb http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_m68k.deb http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_m68k.deb http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_m68k.deb http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_m68k.deb http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_m68k.deb Big endian MIPS: http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_mips.deb http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_mips.deb http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_mips.deb http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_mips.deb http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_mips.deb http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_mips.deb Little endian MIPS: http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_mipsel.deb http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_mipsel.deb http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_mipsel.deb http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_mipsel.deb http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_mipsel.deb http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_mipsel.deb PowerPC: http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_powerpc.deb http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_powerpc.deb http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_powerpc.deb http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_powerpc.deb http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_powerpc.deb http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_powerpc.deb IBM S/390: http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_s390.deb http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_s390.deb http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_s390.deb http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_s390.deb http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_s390.deb http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_s390.deb Sun Sparc: http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.8_sparc.deb http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.8_sparc.deb http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.8_sparc.deb http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.8_sparc.deb http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.8_sparc.deb http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.8_sparc.deb Linux Mandrake Mandrakelinux 9.2 x86 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/9.2/RPMS/perl-5.8.1-0.RC4.3.3.92mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/9.2/RPMS/perl-base-5.8.1-0.RC4.3.3.92mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/9.2/RPMS/perl-devel-5.8.1-0.RC4.3.3.92mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/9.2/RPMS/perl-doc-5.8.1-0.RC4.3.3.92mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/9.2/SRPMS/perl-5.8.1-0.RC4.3.3.92mdk.src.rpm AMD64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/9.2/RPMS/perl-5.8.1-0.RC4.3.3.92mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/9.2/RPMS/perl-base-5.8.1-0.RC4.3.3.92mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/9.2/RPMS/perl-devel-5.8.1-0.RC4.3.3.92mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/9.2/RPMS/perl-doc-5.8.1-0.RC4.3.3.92mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/9.2/SRPMS/perl-5.8.1-0.RC4.3.3.92mdk.src.rpm Mandrakelinux 10.0 x86 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/perl-5.8.3-5.3.100mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/perl-base-5.8.3-5.3.100mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/perl-devel-5.8.3-5.3.100mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/RPMS/perl-doc-5.8.3-5.3.100mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.0/SRPMS/perl-5.8.3-5.3.100mdk.src.rpm AMD64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/perl-5.8.3-5.3.100mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/perl-base-5.8.3-5.3.100mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/perl-devel-5.8.3-5.3.100mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/RPMS/perl-doc-5.8.3-5.3.100mdk.amd64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/amd64/10.0/SRPMS/perl-5.8.3-5.3.100mdk.src.rpm Mandrakelinux 10.1 x86 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/perl-5.8.5-3.3.101mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/perl-base-5.8.5-3.3.101mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/perl-devel-5.8.5-3.3.101mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/RPMS/perl-doc-5.8.5-3.3.101mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/10.1/SRPMS/perl-5.8.5-3.3.101mdk.src.rpm X86_64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/perl-5.8.5-3.3.101mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/perl-base-5.8.5-3.3.101mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/perl-devel-5.8.5-3.3.101mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/RPMS/perl-doc-5.8.5-3.3.101mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/10.1/SRPMS/perl-5.8.5-3.3.101mdk.src.rpm Mandrake Corporate Server 2.1 x86 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/RPMS/perl-5.8.0-14.4.C21mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/RPMS/perl-base-5.8.0-14.4.C21mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/RPMS/perl-devel-5.8.0-14.4.C21mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/RPMS/perl-doc-5.8.0-14.4.C21mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/2.1/SRPMS/perl-5.8.0-14.4.C21mdk.src.rpm X86_64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/RPMS/perl-5.8.0-14.4.C21mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/RPMS/perl-base-5.8.0-14.4.C21mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/RPMS/perl-devel-5.8.0-14.4.C21mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/RPMS/perl-doc-5.8.0-14.4.C21mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/2.1/SRPMS/perl-5.8.0-14.4.C21mdk.src.rpm Mandrake Corporate Server 3.0 x86 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/RPMS/perl-5.8.3-5.3.C30mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/RPMS/perl-base-5.8.3-5.3.C30mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/RPMS/perl-devel-5.8.3-5.3.C30mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/RPMS/perl-doc-5.8.3-5.3.C30mdk.i586.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/3.0/SRPMS/perl-5.8.3-5.3.C30mdk.src.rpm X86_64 ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/3.0/RPMS/perl-5.8.3-5.3.C30mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/3.0/RPMS/perl-base-5.8.3-5.3.C30mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/3.0/RPMS/perl-devel-5.8.3-5.3.C30mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/3.0/RPMS/perl-doc-5.8.3-5.3.C30mdk.x86_64.rpm ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/x86_64/corporate/3.0/SRPMS/perl-5.8.3-5.3.C30mdk.src.rpm SUSE Linux Actualizar mediante YaST Online Update Red Hat Linux Red Hat Desktop (v. 4) Red Hat Enterprise Linux AS (v. 4) Red Hat Enterprise Linux ES (v. 4) Red Hat Enterprise Linux WS (v. 4) https://rhn.redhat.com/ SGI Advanced Linux Environment 3 / RPM / Patch 10258 ftp://oss.sgi.com/projects/sgi_propack/download/3/updates/RPMS Advanced Linux Environment 3 / SRPM / Patch 10258 ftp://oss.sgi.com/projects/sgi_propack/download/3/updates/SRPMS |
|
Identificadores estándar |
|
Propiedad | Valor |
CVE |
CAN-2004-0452 CAN-2004-0976 |
BID | |
Recursos adicionales |
|
Debian Security Advisory DSA-620-1 http://www.debian.org/security/2004/dsa-620 Mandrakesoft Security Advisories MDKSA-2005:031 http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:031 SUSE Security Summary Report SUSE-SR:2005:004 http://www.novell.com/linux/security/advisories/2005_04_sr.html Red Hat Security Advisory RHSA-2005:103-04 https://rhn.redhat.com/errata/RHSA-2005-103.html SGI Security Advisory (20060101-01-U) ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U.asc |
Histórico de versiones |
||
Versión | Comentario | Fecha |
1.0 | Aviso emitido | 2004-12-31 |
1.1 | Aviso emitido por Mandrake (MDKSA-2005:031) | 2005-02-09 |
1.2 | Aviso emitido por SUSE (SUSE-SR:2005:004) | 2005-02-14 |
1.3 | Aviso emitido por Red Hat (RHSA-2005:103-04) | 2005-02-16 |
1.4 | Aviso emitido por SGI (20060101-01-U) | 2006-01-19 |