Fixed in Intrepid via Debian:
perl (5.10.0-11) unstable; urgency=high
* [SECURITY] File::Path::rmtree() no longer makes symlink targets
world-writable. Patch by Ben Hutchings. (Closes: #487319)
-- Niko Tyni <[EMAIL PROTECTED]> Sat, 21 Jun 2008 15:18:50 +0300
** Bug watch added: Debian Bug tracker #487319
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=487319
** Also affects: perl (Debian) via
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=487319
Importance: Unknown
Status: Unknown
** Changed in: perl (Ubuntu)
Status: New => Fix Released
--
[CVE-2008-2827] rmtree() in Perl 5.10 vulnerable to symlink attacks
https://bugs.launchpad.net/bugs/243481
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs