CVE-2013-1667: important rehashing flaw

Dave Mitchell davem at iabyn.com
Wed Mar 13 11:52:59 GMT 2013


On Wed, Mar 13, 2013 at 09:50:56AM +0000, Chisel wrote:
> I've just stumbled across http://www.cpan.org/src/README.html which says:
> 
> Latest releases in each branch of Perl
> 
> Major  Version  Type  Released  Download
> 5.14  5.14.4  Devel  2013-03-07  perl-5.14.4-RC2.tar.gz
> 5.16  5.16.3  Maint  2013-03-11  perl-5.16.3.tar.gz
> 5.14  5.14.4  Maint  2013-03-10  perl-5.14.4.tar.gz
> 
> 
> To me it looks odd having the RC2 there ... should that be dropped
> until there is (another) release candidate?

Presumably its counting 5.14.4-RC2 as the most recent development release,
and when 5.17.10 is released this will be updated?

-- 
The Enterprise's efficient long-range scanners detect a temporal vortex
distortion in good time, allowing it to be safely avoided via a minor
course correction.
    -- Things That Never Happen in "Star Trek" #21


More information about the london.pm mailing list