perl-App-cpanminus-1.7044-14.1.el9_5

エラータID: AXSA:2024-9412:01

Release date: 
Wednesday, December 18, 2024 - 15:40
Subject: 
perl-App-cpanminus-1.7044-14.1.el9_5
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

Why? It's dependency free, requires zero configuration, and stands alone but it's maintainable and extensible with plug-ins and friendly to shell scripting. When running, it requires only 10 MB of RAM.

Security Fix(es):

* perl-App-cpanminus: Insecure HTTP in App::cpanminus Allows Code Execution Vulnerability (CVE-2024-45321)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-45321
The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. perl-App-cpanminus-1.7044-14.1.el9_5.src.rpm
    MD5: 4b523fdefe5189120f6da4cb94b5378d
    SHA-256: 05c390e8a6244b36f7c304f299a0fbdb646b4a2deb3bf313a870df2111bda80e
    Size: 323.97 kB

Asianux Server 9 for x86_64
  1. perl-App-cpanminus-1.7044-14.1.el9_5.noarch.rpm
    MD5: 27e48301aa681b4527cbdf98f425807d
    SHA-256: db36b17b9394e18445ad99673ec89a253d3f6635257086808c098bd2b3854951
    Size: 85.70 kB