Note: This is a beta release of Red Hat Bugzilla 5.0. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Also email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback here.

Bug 156128

Summary: RHSA-2005:103-04 not applied in FC perl
Product: [Fedora] Fedora Reporter: Ville Skyttä <scop>
Component: perlAssignee: Chip Turner <cturner>
Status: CLOSED ERRATA QA Contact: David Lawrence <dkl>
Severity: medium Docs Contact:
Priority: medium    
Version: rawhideCC: jose.p.oliveira.oss, wtogami
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: https://rhn.redhat.com/errata/RHSA-2005-103.html
Whiteboard:
Fixed In Version: 5.8.5-12.FC3 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2005-05-04 21:02:29 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On:    
Bug Blocks: 136450    
Attachments:
Description Flags
FC3 perl update
none
CAN-2004-0452 for both FC-3 and FC-4
none
FC4 perl update
none
CAN-2005-0155+0156 for FC4 none

Description Ville Skyttä 2005-04-27 19:18:04 UTC
The fixes from RHSA-2005:103-04 do not seem to be applied in FC4tX perl
packages, nor in FC3 based on the package changelog. 
https://rhn.redhat.com/errata/RHSA-2005-103.html

Comment 1 Warren Togami 2005-04-28 03:22:35 UTC
It would *really* help if you could prepare the exact patches to apply to FC4
and the spec patch.  I have huge school deadlines right now in addition to
everything else and feeling overwhelmed.

I suppose this is a good reason to issue the FC3 update along with the FCGI fix.
 Anything we added to the FC4 package that would make it unsuitable for the FC3
update, or we can use it pretty much as-is?

Comment 2 Warren Togami 2005-04-28 03:29:25 UTC
Oh we obviously need to drop the CGI patch, but anything else?


Comment 3 Ville Skyttä 2005-04-28 20:17:55 UTC
Created attachment 113807 [details]
FC3 perl update

Ok, here goes the FC-3 perl update.  CAN-2004-0452 was not yet fixed, and I
applied the FCGI and Mac::Files filtering fixes, too.  Additionally, needed to
apply the suidperl release munging removal; in its current state the package
wouldn't even build here (due to my buildroot in ~/.rpmmacros containing
%{release}, rpmbuild got confused about the package's NVR and failed to find
the debug files).

Comment 4 Ville Skyttä 2005-04-28 20:18:57 UTC
Created attachment 113808 [details]
CAN-2004-0452 for both FC-3 and FC-4

From RHEL4.

Comment 5 Ville Skyttä 2005-04-28 20:23:54 UTC
Created attachment 113810 [details]
FC4 perl update

Comment 6 Ville Skyttä 2005-04-28 20:24:48 UTC
Created attachment 113811 [details]
CAN-2005-0155+0156 for FC4

From FC3.

Comment 7 Rob Kearey 2005-04-29 01:53:05 UTC
Problem still occurs in perl-5.8.5-12.FC3

[robk@custard ~]$ perl -e "use CGI::Fast;"
Can't locate FCGI.pm in @INC (etc)

Comment 8 Ville Skyttä 2005-05-04 21:02:29 UTC
Fixed in 5.8.5-12.FC3 and 5.8.6-10.