New Debian perl 5.36.0-7+deb12u3 fixes: This update addresses the following issues: * perl: Perl 5.34, 5.36, 5.38 and 5.40 are vulnerable to a heap buffer overflow when transliterating non-ASCII bytes (CVE-2024-56406) 5.36.0-7+deb12u3 (Fri, 29 Aug 2025 15:09:36 +0300) * [SECURITY] CVE-2023-31484: CPAN.pm now verifies TLS certificates. * [SECURITY] CVE-2025-40909: Clone dirhandles without fchdir
--- mirror/ftp/pool/main/p/perl/perl_5.36.0-7+deb12u2.dsc +++ apt/ucs_5.2-0-errata5.2-3/source/perl_5.36.0-7+deb12u3.dsc @@ -1,3 +1,10 @@ +5.36.0-7+deb12u3 [Fri, 29 Aug 2025 15:09:36 +0300] Niko Tyni <ntyni@debian.org>: + + * [SECURITY] CVE-2023-31484: CPAN.pm now verifies TLS certificates. + (Closes: #1035109) + * [SECURITY] CVE-2025-40909: Clone dirhandles without fchdir + (Closes: #1098226) + 5.36.0-7+deb12u2 [Sat, 12 Apr 2025 18:16:31 +0300] Niko Tyni <ntyni@debian.org>: * [SECURITY] CVE-2024-56406: Fix heap-buffer-overflow with tr// <http://piuparts.knut.univention.de/5.2-3/#2330598840502386000>
OK: YAML OK: Tests OK: piuparts
<https://errata.software-univention.de/#/?erratum=5.2x207>