Debian-Sicherheitsankündigung

DSA-208-1 perl -- unsichere Sandbox

Datum des Berichts:
12. Dez 2002
Betroffene Pakete:
perl
perl-5.004
perl-5.005
Verwundbar:
Ja
Sicherheitsdatenbanken-Referenzen:
In der Bugtraq-Datenbank (bei SecurityFocus): BugTraq ID 6111.
In Mitres CVE-Verzeichnis: CVE-2002-1323.
Weitere Informationen:

In Safe.pm, einem Perl-Standardmodul, wurde eine Sicherheitslücke entdeckt. Das Safe-Modul erlaubt die Erstellung einer Art Sandbox (compartement), in der Perl-Code in einem neuen Namensraum ausgeführt wird und nicht auf Variablen außerhalb dieses Namensraums zugreifen kann. Wenn eine Sandbox jedoch schon einmal benutzt wurde, gibt es keine Garantie, dass sie noch sicher ist, weil es möglich ist, in ihr Code auszuführen, der ihre Sicherheitseinstellungen (operation mask) ändert. Ein Programm, das jede Sandbox nur einmal benutzt, ist von dem Fehler nicht betroffen.

Dieses Problem wurde in Version 5.6.1-8.2 für die aktuelle stable Distribution (Woody), in Version 5.004.05-6.2 und 5.005.03-7.2 für die alte stable Distribution (Potato) und in Version 5.8.0-14 für die unstable Distribution (Sid) behoben.

Wir empfehlen Ihnen, Ihre Perl-Pakete zu aktualisieren.

Behoben in:

Debian GNU/Linux 2.2 (potato)

Quellcode:
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004_5.004.05-6.2.dsc
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004_5.004.05-6.2.diff.gz
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004_5.004.05.orig.tar.gz
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005_5.005.03-7.2.dsc
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005_5.005.03-7.2.diff.gz
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005_5.005.03.orig.tar.gz
Architektur-unabhängige Dateien:
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-doc_5.004.05-6.2_all.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-doc_5.005.03-7.2_all.deb
Alpha:
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004_5.004.05-6.2_alpha.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-base_5.004.05-6.2_alpha.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-debug_5.004.05-6.2_alpha.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-suid_5.004.05-6.2_alpha.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005_5.005.03-7.2_alpha.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-base_5.005.03-7.2_alpha.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-debug_5.005.03-7.2_alpha.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-suid_5.005.03-7.2_alpha.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-thread_5.005.03-7.2_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004_5.004.05-6.2_arm.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-base_5.004.05-6.2_arm.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-debug_5.004.05-6.2_arm.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-suid_5.004.05-6.2_arm.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005_5.005.03-7.2_arm.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-base_5.005.03-7.2_arm.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-debug_5.005.03-7.2_arm.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-suid_5.005.03-7.2_arm.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-thread_5.005.03-7.2_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004_5.004.05-6.2_i386.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-base_5.004.05-6.2_i386.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-debug_5.004.05-6.2_i386.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-suid_5.004.05-6.2_i386.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005_5.005.03-7.2_i386.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-base_5.005.03-7.2_i386.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-debug_5.005.03-7.2_i386.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-suid_5.005.03-7.2_i386.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-thread_5.005.03-7.2_i386.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004_5.004.05-6.2_m68k.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-base_5.004.05-6.2_m68k.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-debug_5.004.05-6.2_m68k.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-suid_5.004.05-6.2_m68k.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005_5.005.03-7.2_m68k.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-base_5.005.03-7.2_m68k.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-debug_5.005.03-7.2_m68k.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-suid_5.005.03-7.2_m68k.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-thread_5.005.03-7.2_m68k.deb
PowerPC:
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004_5.004.05-6.2_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-base_5.004.05-6.2_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-debug_5.004.05-6.2_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-suid_5.004.05-6.2_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005_5.005.03-7.2_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-base_5.005.03-7.2_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-debug_5.005.03-7.2_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-suid_5.005.03-7.2_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-thread_5.005.03-7.2_powerpc.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004_5.004.05-6.2_sparc.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-base_5.004.05-6.2_sparc.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-debug_5.004.05-6.2_sparc.deb
http://security.debian.org/pool/updates/main/p/perl-5.004/perl-5.004-suid_5.004.05-6.2_sparc.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005_5.005.03-7.2_sparc.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-base_5.005.03-7.2_sparc.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-debug_5.005.03-7.2_sparc.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-suid_5.005.03-7.2_sparc.deb
http://security.debian.org/pool/updates/main/p/perl-5.005/perl-5.005-thread_5.005.03-7.2_sparc.deb

Debian GNU/Linux 3.0 (woody)

Quellcode:
http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.2.dsc
http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.2.diff.gz
http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1.orig.tar.gz
Architektur-unabhängige Dateien:
http://security.debian.org/pool/updates/main/p/perl/libcgi-fast-perl_5.6.1-8.2_all.deb
http://security.debian.org/pool/updates/main/p/perl/perl-doc_5.6.1-8.2_all.deb
http://security.debian.org/pool/updates/main/p/perl/perl-modules_5.6.1-8.2_all.deb
Alpha:
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.2_alpha.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.2_alpha.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.2_alpha.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.2_alpha.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.2_alpha.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.2_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.2_arm.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.2_arm.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.2_arm.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.2_arm.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.2_arm.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.2_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.2_i386.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.2_i386.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.2_i386.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.2_i386.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.2_i386.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.2_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.2_ia64.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.2_ia64.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.2_ia64.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.2_ia64.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.2_ia64.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.2_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.2_hppa.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.2_hppa.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.2_hppa.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.2_hppa.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.2_hppa.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.2_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.2_m68k.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.2_m68k.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.2_m68k.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.2_m68k.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.2_m68k.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.2_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.2_mips.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.2_mips.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.2_mips.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.2_mips.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.2_mips.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.2_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.2_mipsel.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.2_mipsel.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.2_mipsel.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.2_mipsel.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.2_mipsel.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.2_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.2_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.2_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.2_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.2_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.2_powerpc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.2_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.2_s390.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.2_s390.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.2_s390.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.2_s390.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.2_s390.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.2_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/p/perl/libperl-dev_5.6.1-8.2_sparc.deb
http://security.debian.org/pool/updates/main/p/perl/libperl5.6_5.6.1-8.2_sparc.deb
http://security.debian.org/pool/updates/main/p/perl/perl_5.6.1-8.2_sparc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-base_5.6.1-8.2_sparc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-debug_5.6.1-8.2_sparc.deb
http://security.debian.org/pool/updates/main/p/perl/perl-suid_5.6.1-8.2_sparc.deb

MD5-Prüfsummen der aufgeführten Dateien stehen in der ursprünglichen Sicherheitsankündigung zur Verfügung.