develooper Front page | perl.perl5.porters | Postings from December 2012

security notice: Storable

From:
Ricardo Signes
Date:
December 5, 2012 15:48
Subject:
security notice: Storable
Message ID:
20121205154811.GD13908@cancer.codesimply.com

A number of times over the years, there's been discussion about Storable as a
vector for attack.  If a user can feed you Storable data that you didn't
expect, he has a good chance of doing nasty things to your program.  This has
been discussed on p5p and at YAPCs, but sadly never made it into the
documentation.

This has been fixed with
http://perl5.git.perl.org/perl.git/commit/664f237a84176c09b20b62dbfe64dd736a7ce05e

A release to CPAN containing this warning will also be made soon.

Thanks to Brian Carlson of cPanel who brought this to our attention.

-- 
rjbs




nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About