MDVSA-2014:235: perl-Plack

Updated perl-Plack package fixes security vulnerability:

Plack::App::File would previously strip trailing slashes off provided
paths. This in combination with the common pattern of serving files
with Plack::Middleware::Static could allow an attacker to bypass a
whitelist of generated files (CVE-2014-5269).

Leave a Reply