Updated perl-Plack package fixes security vulnerability
Publication date: 26 Nov 2014Modification date: 09 Jul 2015
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-5269
Description
Plack::App::File would previously strip trailing slashes off provided paths. This in combination with the common pattern of serving files with Plack::Middleware::Static could allow an attacker to bypass a whitelist of generated files (CVE-2014-5269).
References
SRPMS
3/core
- perl-Plack-1.1.400-2.1.mga3
4/core
- perl-Plack-1.2.900-2.1.mga4