Bug 481163 - Update perl-Devel-StackTrace to >= 1.19 in EPEL5
Summary: Update perl-Devel-StackTrace to >= 1.19 in EPEL5
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: perl-Devel-StackTrace
Version: el5
Hardware: All
OS: Linux
low
medium
Target Milestone: ---
Assignee: Xavier Lamien
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: 481165
TreeView+ depends on / blocked
 
Reported: 2009-01-22 15:10 UTC by Xavier Bachelot
Modified: 2009-02-16 17:23 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-02-16 17:23:30 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Xavier Bachelot 2009-01-22 15:10:19 UTC
perl-Devel-StackTrace is the vector for a DoS attack against rt3 <= 3.6.6. Please update to a non-vulnerable version.

See 
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3502 and http://lists.bestpractical.com/pipermail/rt-announce/2008-June/000158.html for details.

Comment 1 Xavier Lamien 2009-02-01 15:17:53 UTC
Done.
Will close once pushed.

Comment 2 Xavier Bachelot 2009-02-16 17:23:30 UTC
Fixed version pushed to EPEL stable.
Thanks Xavier :-)


Note You need to log in before you can comment on or make changes to this bug.