MGASA-2018-0428

Source
https://advisories.mageia.org/MGASA-2018-0428.html
Import Source
https://advisories.mageia.org/MGASA-2018-0428.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0428
Published
2018-11-03T11:55:18Z
Modified
2018-11-03T11:26:56Z
Summary
Updated perl-Dancer2 packages fix security vulnerabilities
Details

Dancer2 0.206000 addresses several potential security issues. There is a potential RCE with regards to Storable. Dancer2 adds session ID validation to the session engine so that session backends based on Storable can reject malformed session IDs that may lead to exploitation of the RCE. Parsing requests now uses HTTP::Entity::Parser which reduces the amount of code needed and does not require re-parsing the request body.

The perl-Dancer2 package has been updated to version 0.206.0 to fix this issue.

Also, the perl-HTTP-XSCookies, perl-WWW-Form-UrlEncoded, perl-HTTP-MultiPartParser, and perl-HTTP-Entity-Parser dependencies have been added and the perl-Type-Tiny, perl-HTTP-Headers-Fast, perl-JSON-MaybeXS, perl-Cookie-Baker, and perl-Plack dependencies have been updated for the new perl-Dancer2 version.

References
Credits

Affected packages

Mageia:6 / perl-Dancer2

Package

Name
perl-Dancer2
Purl
pkg:rpm/mageia/perl-Dancer2?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.206.0-1.1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / perl-Cookie-Baker

Package

Name
perl-Cookie-Baker
Purl
pkg:rpm/mageia/perl-Cookie-Baker?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.100.0-1.2.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / perl-HTTP-Entity-Parser

Package

Name
perl-HTTP-Entity-Parser
Purl
pkg:rpm/mageia/perl-HTTP-Entity-Parser?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.210.0-1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / perl-HTTP-Headers-Fast

Package

Name
perl-HTTP-Headers-Fast
Purl
pkg:rpm/mageia/perl-HTTP-Headers-Fast?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.210.0-1.1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / perl-HTTP-MultiPartParser

Package

Name
perl-HTTP-MultiPartParser
Purl
pkg:rpm/mageia/perl-HTTP-MultiPartParser?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.20.0-1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / perl-HTTP-XSCookies

Package

Name
perl-HTTP-XSCookies
Purl
pkg:rpm/mageia/perl-HTTP-XSCookies?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.0.21-1.1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / perl-JSON-MaybeXS

Package

Name
perl-JSON-MaybeXS
Purl
pkg:rpm/mageia/perl-JSON-MaybeXS?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.0-1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / perl-Plack

Package

Name
perl-Plack
Purl
pkg:rpm/mageia/perl-Plack?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.700-1.1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / perl-Type-Tiny

Package

Name
perl-Type-Tiny
Purl
pkg:rpm/mageia/perl-Type-Tiny?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.2-1.1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / perl-WWW-Form-UrlEncoded

Package

Name
perl-WWW-Form-UrlEncoded
Purl
pkg:rpm/mageia/perl-WWW-Form-UrlEncoded?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.250.0-1.mga6

Ecosystem specific

{
    "section": "core"
}