{
  "schema_version": "1.7.0",
  "id": "MGASA-2020-0255",
  "published": "2020-06-10T23:59:36Z",
  "modified": "2020-06-10T23:28:02Z",
  "summary": "Updated perl packages fix security vulnerability",
  "details": "This update from 5.28.2 to 5.28.3 fixes bugs several bugs the RPM package\nmanager.\n- Update to 5.23.3\n  (See https://metacpan.org/pod/release/XSAWYERX/perl-5.28.3/pod/perldelta.pod \n  for release notes)\n- Security release fixes CVE-2020-10543, CVE-2020-10878 and CVE-2020-12723\n- Work around a glibc bug in caching LC_MESSAGES (GH#17081)\n- Fix POSIX:setlocale() documentation\n- Prevent from an integer overflow in POSIX::SigSet()\n- Fix thread-safety of IO::Handle (GH#14816)\n- Close :unix PerlIO layers properly (bug #987118)\n- Fix counting a recursion limit when matching in a postponed eval\n  (GH#17490)\n- Fix sorting tied arrays (GH#17496)\n- Fix a spurious warning about a multidimensional syntax (GH#16535)\n- Normalize \"#!/perl\" shebangs in the tests\n- Fix a warning about an uninitialized value in B::Deparse (GH#17537)\n- Fix Time-Local tests to pass after year 2019 (CPAN RT#124787)\n",
  "upstream": [
    "CVE-2020-10543",
    "CVE-2020-10878",
    "CVE-2020-12723"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2020-0255.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=26715"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:7",
        "name": "perl",
        "purl": "pkg:rpm/mageia/perl?arch=source&distro=mageia-7"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "5.28.3-2.mga7"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
