perl-CPAN-2.18-399.el8
エラータID: AXSA:2024-8271:01
Release date:
Saturday, June 15, 2024 - 08:29
Subject:
perl-CPAN-2.18-399.el8
Affected Channels:
Asianux Server 8 for x86_64
Severity:
Moderate
Description:
The CPAN module is a tool to query, download and build perl modules from CPAN sites.
Security Fix(es):
* perl: CPAN.pm does not verify TLS certificates when downloading distributions over HTTPS (CVE-2023-31484)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Asianux Server 8.10 Release Notes linked from the References section.
CVE-2023-31484
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
Solution:
Update packages.
CVEs:
CVE-2023-31484
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
Additional Info:
N/A
Download:
SRPMS
- perl-CPAN-2.18-399.el8.src.rpm
MD5: 1dd6f322390fbee38a0c2cc97659388d
SHA-256: f6e1f21cace7914d17229f67b54ada44f16bb33164d2c29fff748268e15bca70
Size: 805.00 kB
Asianux Server 8 for x86_64
- perl-CPAN-2.18-399.el8.noarch.rpm
MD5: 8a3e33ae2f15707afdd194d614f499e2
SHA-256: c6881d2d413abcb678fc0fed4911f21d3feeb8aeffa72d640f57be541b3f9b35
Size: 553.34 kB