Packages
Get Gentoo!
gentoo.org sites
gentoo.org
Wiki
Bugs
Forums
Packages
Planet
Archives
Sources
Infra Status
Home
Packages
Maintainers
USE flags
Architectures
About
Gentoo Project
Perl Project
Packages
1832
Outdated
215
Pull requests
12
Bugs
323
Security
52
Changelog
Security Bug Reports
<dev-perl/DBI-1.644: insufficient parameter validation in DBD::File
746437 - Assigned to Gentoo Security
<dev-perl/Net-CIDR-Lite-0.220.0: octal type confusion with leading zeros in IP octets
779172 - Assigned to Gentoo Security
dev-perl/App-cpanminus: signature verification bypass
829116 - Assigned to Gentoo Security
<dev-perl/HTTP-Daemon-6.160.0: Incorrect handling of multiple Content-Length headers
908905 - Assigned to Gentoo Security
dev-perl/Mail-Box-POP3: defaults to no SSL verification
913199 - Assigned to Gentoo Security
<dev-perl/Crypt-SMIME-0.300.0: double free in x509 parser
930378 - Assigned to Gentoo Security
<dev-perl/Email-MIME-1.954.0: Denial of service via excessive memory consumption
931106 - Assigned to Gentoo Security
<dev-perl/Net-DNS-1.450.0: DoS vulnerability in TCP handling
931107 - Assigned to Gentoo Security
<dev-perl/Crypt-OpenSSL-RSA-0.350.0: Marvin Attack vulnerability (side-channel)
931108 - Assigned to Gentoo Security
<dev-perl/Module-ScanDeps-1.370.0: Local privilege escalation
945087 - Assigned to Gentoo Security
<dev-lang/perl-5.40.2: Heap buffer overflow
953821 - Assigned to Gentoo Security
<dev-lang/perl-5.42.0: Perl threads have a working directory race condition where file operations may target unintended path
956993 - Assigned to Gentoo Security
<dev-perl/CryptX-0.87.0: Vulnerability in bundled dev-libs/libtommath
958034 - Assigned to Gentoo Security
<dev-perl/Authen-SASL-2.180.0-r1: insufficient entropy in client nonce
960293 - Assigned to Gentoo Security
<dev-perl/Crypt-CBC-3.70.0: May use insecure rand() function for cryptographic functions
960822 - Assigned to Gentoo Security
<dev-perl/JSON-XS-4.40.0: integer overflow
962549 - Assigned to Gentoo Security
<dev-perl/Cpanel-JSON-XS-4.400.0: integer overflow
962550 - Assigned to Gentoo Security
<dev-perl/CGI-Simple-1.282.0: missing sanitization of user-supplied values in HTTP headers
962681 - Assigned to Gentoo Security
dev-perl/XML-Parser: Multiple vulnerabilities
971383 - Assigned to Gentoo Security
<dev-perl/Text-CSV_XS-1.620.0: use-after-free
973376 - Assigned to Gentoo Security
dev-lang/perl: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
976061 - Assigned to Gentoo Security
dev-perl/HTTP-Daemon: OS command injection via send_file()
976110 - Assigned to Gentoo Security
<dev-perl/Cpanel-JSON-XS-4.410.0: Multiple vulnerabilities
976178 - Assigned to Gentoo Security
<dev-perl/Sereal-Decoder-5.6.0: versions before 5.005 for Perl allow heap out-of-bounds read via crafted input
976443 - Assigned to Gentoo Security
<dev-perl/DBI-1.651.0: buffer overflow & stack overflow
977040 - Assigned to Gentoo Security
dev-perl/Crypt-DSA: multiple vulnerabilities
978730 - Assigned to Gentoo Security
<dev-perl/Net-CIDR-Lite-0.240.0: IP ACL bypass
979254 - Assigned to Gentoo Security
<dev-perl/CryptX-0.90.0: does not reseed the Crypt::PK PRNG state after forking
979275 - Assigned to Gentoo Security
dev-perl/Crypt-PasswdMD5: versions through 1.42 for Perl generates insecure random values for salts
979280 - Assigned to Gentoo Security
<virtual/perl-Archive-Tar-3.120.0: multiple vulnerabilities
979294 - Assigned to Gentoo Security
dev-perl/Apache-Session: multiple vulnerabilities
979299 - Assigned to Gentoo Security
<dev-perl/Crypt-PBKDF2-0.261.630: multiple vulnerabilities
979300 - Assigned to Gentoo Security
<virtual/perl-IO-Compress-2.220.0: multiple vulnerabilities
979301 - Assigned to Gentoo Security
<dev-perl/HTTP-Date-6.80.0: CPU exhaustion via polynomial regex backtracking in parse_date
979425 - Assigned to Gentoo Security
<dev-perl/Bytes-Random-Secure-0.290.0-r1: internal state shared across forked processes
979426 - Assigned to Gentoo Security
<dev-perl/String-Util-1.360.0: regular expression denial of service
979427 - Assigned to Gentoo Security
<dev-perl/Net-DNS-1.560.0: multiple vulnerabilities
979439 - Assigned to Gentoo Security
<dev-perl/Config-IniFiles-3.1.0: OS command injection and file overwrite
979587 - Assigned to Gentoo Security
<dev-perl/List-SomeUtils-XS-0.590.0: heap buffer overflow in the pairwise function
979590 - Assigned to Gentoo Security
<dev-perl/JavaScript-Minifier-XS-0.160.0: multiple vulnerabilities
979591 - Assigned to Gentoo Security
<dev-perl/CSS-Minifier-XS-0.140.0: memory leak when the entire document is minified away
979592 - Assigned to Gentoo Security
dev-perl/CGI-Session: predictable session ids from low-entropy sources
979594 - Assigned to Gentoo Security
dev-perl/Crypt-Password: multiple vulnerabilities
979601 - Assigned to Gentoo Security
dev-perl/HTML-Gumbo: heap memory disclosure via type confusion
979603 - Assigned to Gentoo Security
<dev-perl/DBI-1.651.0: multiple vulnerabilities
979616 - Assigned to Gentoo Security
dev-perl/Mojolicious: session CSRF token exposed to BREACH compression oracle
979633 - Assigned to Gentoo Security
<dev-lang/perl-5.44.0: Integer Overflow and Out of Bounds Read
979636 - Assigned to Gentoo Security
dev-perl/YAML-Syck: multiple vulnerabilities
979724 - Assigned to Gentoo Security
dev-perl/XML-LibXML: out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences
979725 - Assigned to Gentoo Security
dev-perl/Plack: generates session ids insecurely
979750 - Assigned to Gentoo Security
dev-perl/Date-Manip: multiple vulnerabilities
980109 - Assigned to Gentoo Security
Contact Information
Please file new vulnerability reports on
Gentoo Bugzilla
and assign them to the Gentoo Security product and Vulnerabilities component.