Re: [SECURITY] perl: CVE-2016-2381

2016-03-08 Thread Yaakov Selkowitz
On 2016-03-08 11:59, Achim Gratz wrote: Achim Gratz writes: Yaakov Selkowitz writes: A security vulnerability has been made public for perl: I've asked on p5p what the plan is for another 5.22 release. If that's too far off, I'll just patch 5.22.1, otherwise I'll wait for these patches (ther

Re: [SECURITY] perl: CVE-2016-2381

2016-03-08 Thread Achim Gratz
Achim Gratz writes: > Yaakov Selkowitz writes: >> A security vulnerability has been made public for perl: > > I've asked on p5p what the plan is for another 5.22 release. If that's > too far off, I'll just patch 5.22.1, otherwise I'll wait for these > patches (there are more fixes on the branch) t

Re: [SECURITY] perl: CVE-2016-2381

2016-03-07 Thread Achim Gratz
Yaakov Selkowitz writes: > A security vulnerability has been made public for perl: I've asked on p5p what the plan is for another 5.22 release. If that's too far off, I'll just patch 5.22.1, otherwise I'll wait for these patches (there are more fixes on the branch) to be released in 5.22.2. Reg

[SECURITY] perl: CVE-2016-2381

2016-03-06 Thread Yaakov Selkowitz
Achim, A security vulnerability has been made public for perl: https://bugzilla.redhat.com/show_bug.cgi?id=1309214 http://pkgs.fedoraproject.org/cgit/rpms/perl.git/plain/perl-5.23.8-remove-duplicate-environment-variables-from-environ.patch?h=f23 -- Yaakov