ddick (email not shown publicly) I'm based out of Melbourne, Australia. I attend the excellent melbourne.pm.org meetings whenever i get the chance, which is not often enough.
I can't figure out how to get a source version of perl with recent security fixes applied to it, or even get a patch to apply to 5.8.8 or similiar. What am i missing?
Google is your friend. Not only did they report the bug, Google-fu tells me Fix is in [activestate.com] 5.10 RC1 and RC2 (haven't looked back into 5.9.x other than 5.9.1, not in).
I haven't heard what if any plan there is for a 5.8.9 as you suggest - CPAN regression testing is pretty busy with 5.10-RC2. Vendors / downstream distros are applying the patch to their 5.8.8+, as they should. If you have a security-critical perl app that isn't carefully untainting user-supplied
-- Bill
# I had a sig when sigs were cool
use Sig;
I just googled for this (Score:1)
I don't know why this isn't hasn't been addressed in an official Perl release. (5.8.9 anyone?)
Re: (Score:1)
Google is your friend.
See comment up and over.
Bill
Bill
# I had a sig when sigs were cool
use Sig;
The patch is in ... but not there yet (Score:1)
Nicholas applied the patch to maint-58 [activestate.com] on 11/06.
I haven't heard what if any plan there is for a 5.8.9 as you suggest - CPAN regression testing is pretty busy with 5.10-RC2. Vendors / downstream distros are applying the patch to their 5.8.8+, as they should. If you have a security-critical perl app that isn't carefully untainting user-supplied
Bill
# I had a sig when sigs were cool
use Sig;
Re: (Score:1)
Re:The patch is in ... AND IS there NOW (Score:1)
Google didn't find the 11/15 p5p msg [perl.org] the other day, but it does now.
Bill
# I had a sig when sigs were cool
use Sig;