perl-CPAN-2.18-399.el8

エラータID: AXSA:2024-8271:01

Release date: 
Saturday, June 15, 2024 - 08:29
Subject: 
perl-CPAN-2.18-399.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

The CPAN module is a tool to query, download and build perl modules from CPAN sites.

Security Fix(es):

* perl: CPAN.pm does not verify TLS certificates when downloading distributions over HTTPS (CVE-2023-31484)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Asianux Server 8.10 Release Notes linked from the References section.

CVE-2023-31484
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. perl-CPAN-2.18-399.el8.src.rpm
    MD5: 1dd6f322390fbee38a0c2cc97659388d
    SHA-256: f6e1f21cace7914d17229f67b54ada44f16bb33164d2c29fff748268e15bca70
    Size: 805.00 kB

Asianux Server 8 for x86_64
  1. perl-CPAN-2.18-399.el8.noarch.rpm
    MD5: 8a3e33ae2f15707afdd194d614f499e2
    SHA-256: c6881d2d413abcb678fc0fed4911f21d3feeb8aeffa72d640f57be541b3f9b35
    Size: 553.34 kB