From: | CARNIL [...] cpan.org |
Subject: | [PATCH] Remove . from @INC when loading modules dynamically |
Hi,
In Debian we are currently applying the following patch to
MIME-EncWords.
We thought you might be interested in it too. Background is at
http://article.gmane.org/gmane.comp.lang.perl.perl5.porters/160507
From e8e8a785b987c78ddee19ed8cc18cb1c70252c87 Mon Sep 17 00:00:00 2001
From: Dominic Hargreaves <dom@earth.li>
Date: Mon, 25 Jul 2016 09:49:23 +0100
Subject: [PATCH] Remove . from @INC when loading modules dynamically
[CVE-2016-1238]
The patch is tracked in our Git repository at
https://anonscm.debian.org/cgit/pkg-perl/packages/libmime-encwords-perl.git/plain/debian/patches/CVE-2016-1238.patch
Thanks for considering,
Salvatore Bonaccorso,
Debian Perl Group