Ubuntu has issued an advisory today (July 14): https://ubuntu.com/security/notices/USN-5520-1 The issue is fixed upstream in 6.15: https://github.com/libwww-perl/HTTP-Daemon/security/advisories/GHSA-cg8c-pxmv-w7cf Mageia 8 is also affected.
Status comment: (none) => Fixed upstream in 6.15Whiteboard: (none) => MGA8TOO
Assigning to our Perl stack maintainers
Assignee: bugsquad => perlCC: (none) => marja11
openSUSE has issued an advisory for this today (August 23): https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MZECADIWJOUORYOQTG5UI5M2TBA2O3BF/
https://cpan.metacpan.org/modules/by-module/HTTP/ doesn't propose 6.15, just 6.14 for now.
Status: NEW => ASSIGNEDCC: (none) => bruno
I think these 3 patches are needed: https://github.com/libwww-perl/HTTP-Daemon/commit/331d5c1d1f0e48e6b57ef738c2a8509b1eb53376.patch https://github.com/libwww-perl/HTTP-Daemon/commit/e84475de51d6fd7b29354a997413472a99db70b2.patch https://github.com/libwww-perl/HTTP-Daemon/commit/8dc5269d59e2d5d9eb1647d82c449ccd880f7fd0.patch From https://github.com/libwww-perl/HTTP-Daemon/issues/56 Pushed to cauldron.
Pushed to updates_testing for mga8
Assignee: perl => qa-bugs
Version: Cauldron => 8
Whiteboard: MGA8TOO => (none)
perl-HTTP-Daemon-6.140-3.mga8
Status comment: Fixed upstream in 6.15 => (none)
perl-HTTP-Daemon-6.140-3.mga8 not found in the remote repository
CC: (none) => herman.viaene
It's there. http://mirrors.kernel.org/mageia/distrib/8/x86_64/media/core/updates_testing/perl-HTTP-Daemon-6.140.0-3.mga8.noarch.rpm
OK, got it now MGA8-64 MATE on Acer Aspire 5253 No installation issues. No previous updates or wiki, so tried # urpmq --whatrequires perl-HTTP-Daemon-6.140.0-3.mga8 fusioninventory-agent perl-Frontier-RPC perl-HTTP-Daemon perl-HTTP-Daemon-SSL perl-HTTP-Proxy perl-Pod-POM-Web perl-Test-HTTP-LocalServer perl-libwww-perl Had a short look at fusioninventory-agent, this is part of managing nodes in a cluster, way beyond me. The rest and the comment in MCC of packagee itself reads as a developer tool. So proposing OK on clean install as it apprently does not disturb anything else.
Whiteboard: (none) => MGA8-64-OK
Validating.
Keywords: (none) => validated_updateCC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => advisoryCC: (none) => davidwhodgins
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2022-0349.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED