https://bugzilla.redhat.com/show_bug.cgi?id=2364066
Bug ID: 2364066
Summary: CVE-2024-58135 perl-Mojolicious: Mojolicious versions
from 7.28 through 9.39 for Perl may generate weak HMAC
session secrets [fedora-40]
Product: Fedora
Version: 40
Status: NEW
Whiteboard: {"flaws": ["a53a0372-1a9f-412e-9645-c9a8bb2afc69"]}
Component: perl-Mojolicious
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: emmanuel(a)seyman.fr
Reporter: kdudka(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: emmanuel(a)seyman.fr,
perl-devel(a)lists.fedoraproject.org,
robinlee.sysu(a)gmail.com, yaneti(a)declera.com
Blocks: 2363873
Target Milestone: ---
Classification: Fedora
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2363873
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2364066
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2355244
Bug ID: 2355244
Summary: CVE-2025-27552 perl-DBIx-Class-EncodedColumn:
DBIx::Class::EncodedColumn until 0.00032 for Perl uses
insecure rand() function for salting password hashes
in Crypt/Eksblowfish/Bcrypt.pm [fedora-40]
Product: Fedora
Version: 40
Status: NEW
Whiteboard: {"flaws": ["c7185397-7db4-4534-a645-2ac875052cf1"]}
Component: perl-DBIx-Class-EncodedColumn
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: jplesnik(a)redhat.com
Reporter: ahanwate(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: iarnell(a)gmail.com, jplesnik(a)redhat.com,
perl-devel(a)lists.fedoraproject.org
Blocks: 2355041
Target Milestone: ---
Classification: Fedora
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2355041
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2355244
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2355242
Bug ID: 2355242
Summary: CVE-2025-27551 perl-DBIx-Class-EncodedColumn:
DBIx::Class::EncodedColumn until 0.00032 for Perl uses
insecure rand() function for salting password hashes
in Digest.pm [fedora-40]
Product: Fedora
Version: 40
Status: NEW
Whiteboard: {"flaws": ["900c86bc-36d1-4941-89a7-d095f888098d"]}
Component: perl-DBIx-Class-EncodedColumn
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: jplesnik(a)redhat.com
Reporter: ahanwate(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: iarnell(a)gmail.com, jplesnik(a)redhat.com,
perl-devel(a)lists.fedoraproject.org
Blocks: 2355043
Target Milestone: ---
Classification: Fedora
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2355043
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2355242
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2332242
Bug ID: 2332242
Summary: CVE-2024-55918 perl-Graphics-ColorNames: HTML
injection [fedora-40]
Product: Fedora
Version: 40
Status: NEW
Whiteboard: {"flaws": ["39c04a19-4932-4492-ba5e-9a8f0ae95fb4"]}
Component: perl-Graphics-ColorNames
Keywords: Security, SecurityTracking
Severity: medium
Priority: medium
Assignee: jplesnik(a)redhat.com
Reporter: ahanwate(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: jplesnik(a)redhat.com,
perl-devel(a)lists.fedoraproject.org, steve(a)silug.org
Blocks: 2332239
Target Milestone: ---
Classification: Fedora
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2332239
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2332242
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2316684
Bug ID: 2316684
Summary: Request for packaging of Perl module Mail::DMARC
Product: Fedora
Version: 40
OS: Linux
Status: NEW
Component: perl
Severity: medium
Assignee: jplesnik(a)redhat.com
Reporter: thom.jeera(a)proton.me
QA Contact: extras-qa(a)fedoraproject.org
CC: iarnell(a)gmail.com, jplesnik(a)redhat.com, kasal(a)ucw.cz,
mmaslano(a)redhat.com, mspacek(a)redhat.com,
perl-devel(a)lists.fedoraproject.org, ppisar(a)redhat.com,
psabata(a)redhat.com, rhughes(a)redhat.com,
spotrh(a)gmail.com
Target Milestone: ---
Classification: Fedora
spamassassin DMARC plugin (Mail::SpamAssassin::Plugin::DMARC, one of the
default plugins) requires this module.
Error messages (reduced):
Oct 5 16:20:09.892 [1302135] dbg: plugin: loading
Mail::SpamAssassin::Plugin::DMARC from @INC
...
Oct 5 16:20:11.810 [1302135] dbg: DMARC: cannot load Mail::DMARC::PurePerl:
module: Can't locate Mail/DMARC/PurePerl.pm in @INC (you may need to install
the Mail::DMARC::PurePerl module) ...
Oct 5 16:20:11.810 [1302135] dbg: DMARC: Mail::DMARC::PurePerl is required for
DMARC checks, DMARC checks disabled
Reproducible: Always
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2316684
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…