perl-IO-Compress-2.102-4.el9_8.1
エラータID: AXSA:2026-1440:02
リリース日:
2026/08/04 Tuesday - 16:01
題名:
perl-IO-Compress-2.102-4.el9_8.1
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- perl-IO-Compress には、ローカルの攻撃者により、巧妙に細工
された glob を介して、影響を受けるプロセスの権限で任意の perl
コードの実行を可能とする脆弱性が存在します。(CVE-2026-48962)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-48962
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.
追加情報:
N/A
ダウンロード:
SRPMS
- perl-IO-Compress-2.102-4.el9_8.1.src.rpm
MD5: a54665f35d150093f080a41b5ad5c90c
SHA-256: 6250eaf67bad0cf278e81a8c71748d8bb2fea395b6d90d40b5a262457b63cbce
Size: 302.81 kB
Asianux Server 9 for x86_64
- perl-IO-Compress-2.102-4.el9_8.1.noarch.rpm
MD5: dbb7e9f4a7f37429d7c7d18fcfe0da6e
SHA-256: 290ca5a6bbcb1fcd6a62af09de1851148ac21405d4be67a79cb50af64ef3346f
Size: 269.60 kB