perl security fix creates login problems for neomail

Wouter van Gils <[email protected]> Tue, 20 Apr 2004 15:31:09 +0200
Newsgroups gmane.mail.neomail.general
Message-ID <[email protected]>
Hi,

I use a debian woody system with 2.4.26, neomail 1.27 and perl 5.6.1.
Today, debian issued a security release for Perl
(http://www.debian.org/security/2004/dsa-431)

However, after upgrading Perl and trying to login to neomail the
following error occurs: "Can't access() script" (from apache log).

More of you must have the same problem. How should I fix this one...?

Any help would be appriciated!

- Wouter van Gils


*** INFO ON THE BUG ***
Paul Szabo discovered a number of similar bugs in suidperl, a helper
program to run perl scripts with setuid privileges. By exploiting
these bugs, an attacker could abuse suidperl to discover information
about files (such as testing for their existence and some of their
permissions) that should not be accessible to unprivileged users.

For the current stable distribution (woody) this problem has
been fixed in version 5.6.1-8.6.

For the unstable distribution, this problem will be fixed
soon. Refer to Debian bug #220486.

We recommend that you update your perl package if you
have the "perl-suid" package installed.
*********************************************************************



-- 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Wouter van Gils -=- [email protected]
http://the-construct.cx/
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



-------------------------------------------------------
This SF.Net email is sponsored by: IBM Linux Tutorials
Free Linux tutorial presented by Daniel Robbins, President and CEO of
GenToo technologies. Learn everything from fundamentals to system
administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click