看板FB_security
标 题old perl vulnerabilitiy
发信站Tern (Sat Mar 16 01:30:20 2013)
转信站ptt!csnews.cs.nctu!news.cs.nctu!.cs.nctucs.nctu!!freebsdfreebsd.org!ow
Hello Freebsd-security,
I've got portaudit alarm on perl-5.8.9_7 with regard to
perl -- denial of service via algorithmic complexity attack on hashing routines.
Reference:
http://portaudit.FreeBSD.org/68c1f75b-8824-11e2-9996-c48508086173.html
But on the other server I have perl-threaded-5.8.9_7
and portaudit thinks that it is OK (no problem)
Is it correct?
It seems to me that threaded perl also should have the same problem.
Please advise.
PS. I know that it is old and "unsupported" but I don't want to
upgrade without serious reason. And, any way, the "behavior" of
portaudit seems to me not correct.
With best regards,
Alexandre Krasnov.
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"