[SECURITY] Fedora 20 Update: perl-Mojolicious-5.49-1.fc20

updates at fedoraproject.org updates at fedoraproject.org
Wed Oct 22 08:51:13 UTC 2014


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2014-12719
2014-10-12 13:10:41
--------------------------------------------------------------------------------

Name        : perl-Mojolicious
Product     : Fedora 20
Version     : 5.49
Release     : 1.fc20
URL         : http://mojolicious.org/
Summary     : A next generation web framework for Perl
Description :
Back in the early days of the web there was this wonderful Perl library
called CGI, many people only learned Perl because of it. It was simple
enough to get started without knowing much about the language and powerful
enough to keep you going, learning by doing was much fun. While most of the
techniques used are outdated now, the idea behind it is not. Mojolicious is
a new attempt at implementing this idea using state of the art technology.

--------------------------------------------------------------------------------
Update Information:

This version of Mojolicious fixes an assumption in CGI's parameter handling that can result in parameter injection attacks.
--------------------------------------------------------------------------------
ChangeLog:

* Sun Oct 12 2014 Emmanuel Seyman <emmanuel at seyman.fr> - 5.49-1
- Update to 5.49 (fixes a serious security issue)
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use
su -c 'yum update perl-Mojolicious' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list