Bug 57716 - perl: Multiple issues (5.0)
Summary: perl: Multiple issues (5.0)
Status: CLOSED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: Security updates
Version: UCS 5.0
Hardware: All Linux
: P3 normal
Target Milestone: UCS 5.0-9-errata
Assignee: Quality Assurance
QA Contact: Iván.Delgado
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-11-04 11:15 CET by Quality Assurance
Modified: 2024-11-06 18:15 CET (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID:
Max CVSS v3 score: 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2024-11-04 11:15:18 CET
New Debian perl 5.28.1-6+deb10u2 fixes:
This update addresses the following issues:
5.28.1-6+deb10u2 (Sun, 20 Oct 2024 17:24:24 +0000)
* Non maintainer upload by the ELTS team
* Fix CVE-2020-16156: An attacker can prepend checksums for modified packages  to the beginning of CHECKSUMS files, before the cleartext PGP headers. This  makes the Module::Signature::_verify() checks in both cpan and cpanm pass.  Without the sigtext and plaintext arguments to _verify(), the _compare()  check is bypassed. This results in _verify() only checking that valid  signed cleartext is present somewhere in the file.
* Fix CVE-2023-31484: CPAN.pm does not verify TLS certificates when  downloading distributions over HTTPS.
Comment 1 Quality Assurance univentionstaff 2024-11-04 12:00:16 CET
--- mirror/ftp/pool/main/p/perl/perl_5.28.1-6+deb10u1.dsc
+++ apt/ucs_5.0-0-errata5.0-9/source/perl_5.28.1-6+deb10u2.dsc
@@ -1,3 +1,21 @@
+5.28.1-6+deb10u2 [Sun, 20 Oct 2024 17:24:24 +0000] Bastien Roucariès <rouca@debian.org>:
+
+  * Non maintainer upload by the ELTS team
+  * Fix CVE-2020-16156:
+    An attacker can prepend checksums for modified
+    packages to the beginning of CHECKSUMS files,
+    before the cleartext PGP headers. This makes
+    the Module::Signature::_verify() checks
+    in both cpan and cpanm pass.
+    Without the sigtext and plaintext arguments
+    to _verify(), the _compare() check is bypassed.
+    This results in _verify() only checking that
+    valid signed cleartext is present somewhere
+    in the file.
+  * Fix CVE-2023-31484:
+    CPAN.pm does not verify TLS certificates
+    when downloading distributions over HTTPS.
+
 5.28.1-6+deb10u1 [Tue, 21 Jul 2020 20:27:00 +0100] Dominic Hargreaves <dom@earth.li>:
 
   * Multiple regexp security fixes (Closes: #962005)

<http://piuparts.knut.univention.de/5.0-9/#6495825273536911697>
Comment 2 Iván.Delgado univentionstaff 2024-11-05 16:04:52 CET
OK: bug
OK: yaml
OK: announce_errata
OK: patch
OK: piuparts

[5.0-9] 3ad833e617 Bug #57716: perl 5.28.1-6+deb10u2
 doc/errata/staging/perl.yaml | 16 ++++++++++++++++
 1 file changed, 16 insertions(+)