Subject: | Fwd: Embperl security bug |
Date: | Tue, 7 Jan 2014 11:17:24 +1100 |
To: | bug-Embperl [...] rt.cpan.org |
From: | Wire Ghoul <wireghoul [...] gmail.com> |
Hello there,
I hope this is the right address for reporting this. I already reported it
to debian, but it does not appear to have made it upstream to their perl
maintainers list so I thought I would try a direct approach.
The embperl package reveals the full path of the webroot when displaying a
404 message. The offending code appears to be defined at:
Embperl-2.4.0/epmain.c:137: case rcNotFound: msg
="[%d]ERR: %d: %s Not found '%s', searched: %s" ; break ;
Although there may be other instances as well. The full details can be
found through the original Debian bug report:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=731996
Cheers,
Eldar "Wireghoul" Marcussen