Re: Patch for Data::Dumper - CVE-2014-4330

2014-10-25 Thread Ingo Schwarze
Hi Alexander, Alexander Bluhm wrote on Fri, Oct 24, 2014 at 10:55:07PM +0200: On Fri, Oct 24, 2014 at 10:40:55PM +0200, Alexander Bluhm wrote: Here is the diff that applies to -current. I have compared it with the perl git and with Data::Dumper on CPAN. It looks correct. Confirmed. I

Re: Patch for Data::Dumper - CVE-2014-4330

2014-10-25 Thread Andrew Fresh
Although I don't have time to look in great detail, it seems ok on my phone. It should not effect the update to 5.20 which looks pretty good (apart from vax). Hopefully being away from the computer this weekend will make my brain grok gdb and vax enough after work that I can get 5.20 moving

Re: Patch for Data::Dumper - CVE-2014-4330

2014-10-24 Thread Alexander Bluhm
On Fri, Oct 24, 2014 at 10:40:55PM +0200, Alexander Bluhm wrote: Here is the diff that applies to -current. I have compared it with the perl git and with Data::Dumper on CPAN. It looks correct. I have forgotten to cvs add dist/Data-Dumper/t/recurse.t so here is the diff with the new test.

Patch for Data::Dumper - CVE-2014-4330

2014-10-23 Thread Maximilian Pascher
Hi, I created a patch for CVE-2014-4330 in Data::Dumper, Version 2.145. Derived from http://perl5.git.perl.org/perl.git/commitdiff/19be3be6968e2337bcdfe480693fff795ecd1304 See below. Regards, Max Pascher --- gnu/usr.bin/perl/MANIFEST.orig Tue Sep 30 08:51:52 2014 +++ gnu/usr.bin/perl