[USN-3684-1] Perl vulnerability


–===============8546437771327771128==
Content-Type: multipart/signed; micalg=”pgp-sha256″;
protocol=”application/pgp-signature”; boundary=”=-+vAlGQLgw+1VFdPOUl0e”

–=-+vAlGQLgw+1VFdPOUl0e
Content-Type: text/plain; charset=”UTF-8″
Content-Transfer-Encoding: quoted-printable

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Ubuntu Security Notice USN-3684-1
June 13, 2018

perl vulnerability
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.04 LTS
– Ubuntu 17.10
– Ubuntu 16.04 LTS
– Ubuntu 14.04 LTS

Summary:

Perl could be made to overwrite arbitrary files if it received
a specially crafted archive file.

Software Description:
– perl: Practical Extraction and Report Language

Details:

It was discovered that Perl incorrectly handled certain archive files.
An attacker could possibly use this to overwrite arbitrary files.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
=C2=A0 perl=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A05.26.1-6ubuntu0.1

Ubuntu 17.10:
=C2=A0 perl=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A05.26.0-8ubuntu1.2

Ubuntu 16.04 LTS:
=C2=A0 perl=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A05.22.1-9ubuntu0.5

Ubuntu 14.04 LTS:
=C2=A0 perl=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A05.18.2-2ubuntu1.6

In general, a standard system update will make all the necessary
changes.

References:
=C2=A0 https://usn.ubuntu.com/usn/usn-3684-1
=C2=A0 CVE-2018-12015

Package Information:
=C2=A0 https://launchpad.net/ubuntu/+source/perl/5.26.1-6ubuntu0.1
=C2=A0 https://launchpad.net/ubuntu/+source/perl/5.26.0-8ubuntu1.2
=C2=A0 https://launchpad.net/ubuntu/+source/perl/5.22.1-9ubuntu0.5
=C2=A0 https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.6
–=-+vAlGQLgw+1VFdPOUl0e
Content-Type: application/pgp-signature; name=”signature.asc”
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAABCAAGBQJbIVl+AAoJEEW851uECx9phKIP/iw6ZQ4DJU2z0F+XxUU08XPd
QOZQUzMyRpu6nMMr0hhcUuvUr82KDwMqws4DN04WvmHd8cZr1kOHCKIpUxRZha2+
o57SsqByjRNRLnhwbBAeMbRu+PZWasTT7JMeHQI35ErmTW41mOnIkUxzVNyLwlLv
Nig+vf4+2RxRQ6aisjDPBlqSWdJf3DsFy0DNI4fsSd+j9rgjU1Tj1a/0M/zmSqL+
sGNbPAoVvZdEN5NDFjCP8ec7E03gn0DjC+m1kripdUrpz5xsTqoE8q4wNKEV7v7A
rwHXd8JINM+LAR+JQqUmj/Sd/y8BL3gwbfj03a2y5zhg7t3x4NaXM/6tY0xBYWf7
aRF0DvGb+RRKRhOn/mKNbUKQBlq+4UsK8ilG5oLvyt2iRLFFRCi6lRbrz+PBnAm2
1DXU2BtB4MYc6XfwRF0glssoJmw139UbytG/ZeMPnEdCF3aPuOHeY4HkjiSyv13W
8NEZUVNH218bjGyDojTlJoE7dH6sLpWsTdUemXEEicjWZ6c9HBvVRfSTYXhKjnI4
gdFhNfmIt2GIcWFNyc5Zi77EXc5FJQG/0+u7TyLiVusDL9JY8r1Q5PYRPZuIQ+1V
URqG2/DkhyCqrT/5JFL8JKWp3lG6triabQGROvtkZjJ/Gy+7S4qfVZTtrTzajb3I
7XS6AIpDOZr8rSJt1dYO
=YVbt
—–END PGP SIGNATURE—–

–=-+vAlGQLgw+1VFdPOUl0e–

–===============8546437771327771128==
Content-Type: text/plain; charset=”utf-8″
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

–===============8546437771327771128==–