develooper Front page | perl.perl5.porters | Postings from March 2007

Re: Isn't it High Time for perl-5.8.9?

Thread Previous
From:
Dave Mitchell
Date:
March 11, 2007 15:40
Subject:
Re: Isn't it High Time for perl-5.8.9?
Message ID:
20070311224117.GB22434@iabyn.com
On Mon, Mar 12, 2007 at 12:26:17AM +0200, Shlomi Fish wrote:
> Another bug that I'm aware of is:
> 
> http://use.perl.org/~Shlomi+Fish/journal/31775
> 
> It existed in the entire perl-5.8.x branch and may have some security 
> implications.

The bug is fixed in bleed, but the fix is too complex to be back-ported to
to the maint branch. I don't believe it has any security complications.
Okay, so it segfaults. There are many ways to segfault a 5.8.x
interpreter.
If you have a system where an intruder can can cause your interpreter to
compile code of his choice, then a segfault is the least of your worries.

-- 
That he said that that that that is is is debatable, is debatable.

Thread Previous


nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About