summaryrefslogtreecommitdiffstats
path: root/package/perl/0001-PATCH-Remove-existing-files-before-overwriting-them.patch
Commit message (Collapse)AuthorAgeFilesLines
* perl: add upstream security fix for CVE-2018-12015Peter Korsgaard2018-06-131-0/+46
Fixes CVE-2018-12015 - In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name. Patch from https://github.com/jib/archive-tar-new/commit/ae65651eab053fc6dc4590dbb863a268215c1fc5 with path rewritten to match perl tarball. Signed-off-by: Peter Korsgaard <peter@korsgaard.com> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
OpenPOWER on IntegriCloud