Bug#450456: perl: DSA 1400-1: heap overflow

2007-11-07 Thread Brendan O'Dea
On Thu, Nov 08, 2007 at 12:09:30AM +1100, Steffen Joeris wrote: Package: perl The patch used for this update is below. The CVE number is CVE-2007-5116. Please mention it in your changelog, when you fix this bug. Thanks, will apply and build tonight. --bod -- To UNSUBSCRIBE, email to [EMAIL

Bug#450456: perl: DSA 1400-1: heap overflow

2007-11-07 Thread Steffen Joeris
Package: perl Version: 5.8.8-11.1 Severity: grave Tags: security Justification: user security hole Hi There has been a DSA for perl. Will Drewry and Tavis Ormandy of the Google Security Team have discovered a UTF-8 related heap overflow in Perl's regular expression compiler, probably allowing